Splunk® DB Connect

Deploy and Use Splunk DB Connect


description = <string>
# optional
# short description about the input template

interval = <integer|string>
# required
# interval to fetch data from DB and index them in Splunk
# It could be a number of seconds or a cron expression

sourcetype = <string>
# required
# source type associated to events indexed

mode = [batch|rising]
# required
# Operational mode.

query = <string>
# required
# SQL statement to retrieve data from the database

rising_column_index = <integer>
# required in rising mode
# The column number of the rising column you specified (1-based).

input_timestamp_column_index = <integer>
# required when the index_time_mode is dbColumn
# The column number of the timestamp column you specified (1-based).

input_timestamp_format = <value>
# optional
# specify the format of input timestamp column, in JavaSimpleDateString format.
# with index_time_mode as dbColumn, if this property is provided then DBX will use ResultSet#getString to get the value
# and try to parse the timestamp with given format, else if this property is not persent DBX will try to use ResultSet#getTimestamp
# to get the timestamp.

index_time_mode = [current|dbColumn]
# required
# Specifies how to set the index time.
# current: use current time as index time
# dbColumn: use a DB column as index time.

input_type = [event|metric]
# optional
# Defines which type of metric template tracks. If not given default value is event.

connection_type = <string>
# optional
# Defines for which connection type the template will be shown. If empty - will be shown for all connections.
Last modified on 19 July, 2023
db_inputs.conf.spec   db_outputs.conf.spec

This documentation applies to the following versions of Splunk® DB Connect: 3.14.0, 3.14.1, 3.15.0, 3.16.0, 3.17.0, 3.17.1, 3.17.2

Was this topic useful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters