Hi
Issue: I am trying to index data from sql server, but not able to add data to index.
In splunk I am able to fetch sql server data using “SQL Explorer” and “dbquery”.
To index sqlserver data with splunk, I created “Input” by passing appropriate parameters, but it did not work for me.
Application: Splunk DB Connect 3.0.3 (on Linux server)
Please provide your inputs
Entries with db_inputs.conf file, I also tried to add data to default index as well as custom index. But did not get any success.
[Input_db_log]
connection = Logging
fetch_size = 100
index = idxmssql
input_timestamp_column_fullname = (002) Log.Date.datetime
input_timestamp_column_name = Date
interval = */3 * * * *
max_rows = 1000
mode = advanced
query = SELECT * FROM "Sitecore.Logging"."dbo"."Log" where id > ? order by id
sourcetype = dbx
tail_rising_column_name = ID
ui_query_catalog = Sitecore.Logging
ui_query_mode = advanced
ui_query_schema = dbo
ui_query_table = Log
... View more