<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk DB Connect -- Checkpoint Set To Null in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-DB-Connect-Checkpoint-Set-To-Null/m-p/340811#M41104</link>
    <description>&lt;P&gt;Or do this &lt;A href="https://answers.splunk.com/answers/775568/can-splunk-index-gzipd-xmls-from-a-sql-database.html"&gt;https://answers.splunk.com/answers/775568/can-splunk-index-gzipd-xmls-from-a-sql-database.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 10 Oct 2019 19:42:55 GMT</pubDate>
    <dc:creator>nick405060</dc:creator>
    <dc:date>2019-10-10T19:42:55Z</dc:date>
    <item>
      <title>Splunk DB Connect -- Checkpoint Set To Null</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-DB-Connect-Checkpoint-Set-To-Null/m-p/340798#M41091</link>
      <description>&lt;P&gt;I am trying to collect SQL Trace logs using Splunk DB Connect 3.1.1.&lt;BR /&gt;
I am currently using the Splunk Add-On for Microsoft SQL Server's mssql:trclog template for the query.&lt;BR /&gt;
I am currently using StartTime as the rising column.&lt;BR /&gt;
However, after applying the settings, I am only able to collect 2000 events once, and it stopped collecting, even when I set the frequency to 60 seconds.&lt;BR /&gt;
Upon searching the logs in splunk_app_db_connect_server.log, I realized that the checkpoint is  set to null after the first collection.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2017-11-01 16:58:50.447 +0800  [QuartzScheduler_Worker-27] INFO  c.s.d.s.dbinput.task.DbInputCheckpointRepository - action=load_checkpoint_from_cache checkpoint=Checkpoint{value='2017-11-01 16:48:00.000', appVersion='3.1.1', columnType=93, timestamp='2017-11-01T16:58:32.010+08:00'}
2017-11-01 16:58:50.447 +0800  [QuartzScheduler_Worker-27] INFO  c.s.d.s.dbinput.task.DbInputCheckpointRepository - action=load_checkpoint_from_cache checkpoint=Checkpoint{value='2017-11-01 16:48:00.000', appVersion='3.1.1', columnType=93, timestamp='2017-11-01T16:58:32.010+08:00'}
2017-11-01 16:58:50.634 +0800  [QuartzScheduler_Worker-27] INFO  c.s.d.s.dbinput.task.DbInputCheckpointRepository - action=dump_checkpoint file=C:\Program Files\Splunk\var\lib\splunk\modinputs\server\splunk_app_db_connect\sqltrace value={"value":null,"appVersion":"3.1.1","columnType":93,"timestamp":"2017-11-01T16:58:50.447+08:00"}
2017-11-01 16:58:50.712 +0800  [QuartzScheduler_Worker-27] INFO  c.s.d.s.dbinput.task.DbInputCheckpointRepository - action=save_checkpoint_success checkpoint=Checkpoint{value='null', appVersion='3.1.1', columnType=93, timestamp='2017-11-01T16:58:50.447+08:00'}
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;May I know why is this happening?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:32:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-DB-Connect-Checkpoint-Set-To-Null/m-p/340798#M41091</guid>
      <dc:creator>yujietay</dc:creator>
      <dc:date>2020-09-29T16:32:19Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB Connect -- Checkpoint Set To Null</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-DB-Connect-Checkpoint-Set-To-Null/m-p/340799#M41092</link>
      <description>&lt;P&gt;I changed my rising column to use EventSequence, but it still does not work.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2017 04:31:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-DB-Connect-Checkpoint-Set-To-Null/m-p/340799#M41092</guid>
      <dc:creator>yujietay</dc:creator>
      <dc:date>2017-11-02T04:31:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB Connect -- Checkpoint Set To Null</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-DB-Connect-Checkpoint-Set-To-Null/m-p/340800#M41093</link>
      <description>&lt;P&gt;Have you added order by timestamp as part of your SQL query?&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2017 07:42:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-DB-Connect-Checkpoint-Set-To-Null/m-p/340800#M41093</guid>
      <dc:creator>peterchenadded</dc:creator>
      <dc:date>2017-11-02T07:42:37Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB Connect -- Checkpoint Set To Null</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-DB-Connect-Checkpoint-Set-To-Null/m-p/340801#M41094</link>
      <description>&lt;P&gt;Hi peterchenadded,&lt;/P&gt;

&lt;P&gt;Yes, the query goes like this:&lt;BR /&gt;
&lt;CODE&gt;SELECT * &lt;BR /&gt;
FROM fn_trace_gettable('C:\\\\Program Files\\\\Microsoft SQL Server\\\\MSSQL11.MSSQLSERVER\\\\MSSQL\\\\Log\\\\log.trc',default) &lt;BR /&gt;
WHERE StartTime &amp;gt; ? &lt;BR /&gt;
ORDER BY StartTime ASC&lt;BR /&gt;
&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2017 08:36:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-DB-Connect-Checkpoint-Set-To-Null/m-p/340801#M41094</guid>
      <dc:creator>yujietay</dc:creator>
      <dc:date>2017-11-02T08:36:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB Connect -- Checkpoint Set To Null</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-DB-Connect-Checkpoint-Set-To-Null/m-p/340802#M41095</link>
      <description>&lt;P&gt;Can you check the format of StartTime? To make sure they are all valid and consistent. DBX might be failing to parse an unexpected StartTime value.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2017 21:21:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-DB-Connect-Checkpoint-Set-To-Null/m-p/340802#M41095</guid>
      <dc:creator>peterchenadded</dc:creator>
      <dc:date>2017-11-02T21:21:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB Connect -- Checkpoint Set To Null</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-DB-Connect-Checkpoint-Set-To-Null/m-p/340803#M41096</link>
      <description>&lt;P&gt;The format of StartTime is datetime, which DBX should be able to parse. I also tried the same thing for EventSequence, which is bigint format.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2017 01:35:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-DB-Connect-Checkpoint-Set-To-Null/m-p/340803#M41096</guid>
      <dc:creator>yujietay</dc:creator>
      <dc:date>2017-11-03T01:35:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB Connect -- Checkpoint Set To Null</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-DB-Connect-Checkpoint-Set-To-Null/m-p/340804#M41097</link>
      <description>&lt;P&gt;I know this is a bit of an older thread but was wondering if you were able to find a resolution for this issue? I am currently experience the same issue with collecting trace file logs via DB Connect. I get one good pull and then nothing.  After reviewing our ../splunk/var/lib/splunk/modinputs/server/splunk_app_db_connect/ file the checkpoint value is "null". TIA&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:40:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-DB-Connect-Checkpoint-Set-To-Null/m-p/340804#M41097</guid>
      <dc:creator>jay_morris</dc:creator>
      <dc:date>2020-09-29T17:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB Connect -- Checkpoint Set To Null</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-DB-Connect-Checkpoint-Set-To-Null/m-p/340805#M41098</link>
      <description>&lt;P&gt;I have yet to find a resolution to this, but I just submitted a case to Splunk recently. Hopefully this will be resolved soon.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2018 02:31:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-DB-Connect-Checkpoint-Set-To-Null/m-p/340805#M41098</guid>
      <dc:creator>yujietay</dc:creator>
      <dc:date>2018-01-17T02:31:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB Connect -- Checkpoint Set To Null</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-DB-Connect-Checkpoint-Set-To-Null/m-p/340806#M41099</link>
      <description>&lt;P&gt;So it looks like it is a known bug when returning non-indexable columns.  I found it in the known issues section under the release notes for 3.1.1 (&lt;A href="http://docs.splunk.com/Documentation/DBX/3.1.1/ReleaseNotes/Releasenotes"&gt;DBX-4454&lt;/A&gt;).  The work around is to remove those columns that contain the binary data.  If you run your test query while editing inputs you should see some values like "&lt;EM&gt;Non-Displayable Column Type image&lt;/EM&gt;".  Remove those columns and your checkpoint will update.&lt;/P&gt;

&lt;P&gt;I hope that helps.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2018 21:58:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-DB-Connect-Checkpoint-Set-To-Null/m-p/340806#M41099</guid>
      <dc:creator>jay_morris</dc:creator>
      <dc:date>2018-01-17T21:58:52Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB Connect -- Checkpoint Set To Null</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-DB-Connect-Checkpoint-Set-To-Null/m-p/340807#M41100</link>
      <description>&lt;P&gt;So it looks like it is a known bug when returning non-indexable columns.  I found it in the known issues section under the release notes for 3.1.1 (&lt;A href="http://docs.splunk.com/Documentation/DBX/3.1.1/ReleaseNotes/Releasenotes"&gt;DBX-4454&lt;/A&gt;).  The work around is to remove those columns that contain the binary data.  If you run your test query while editing inputs you should see some values like "&lt;EM&gt;Non-Displayable Column Type image&lt;/EM&gt;".  Remove those columns and your checkpoint will update.&lt;/P&gt;

&lt;P&gt;I hope that helps.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2018 22:08:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-DB-Connect-Checkpoint-Set-To-Null/m-p/340807#M41100</guid>
      <dc:creator>jay_morris</dc:creator>
      <dc:date>2018-01-17T22:08:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB Connect -- Checkpoint Set To Null</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-DB-Connect-Checkpoint-Set-To-Null/m-p/340808#M41101</link>
      <description>&lt;P&gt;Thanks jay_morris, that works!&lt;/P&gt;

&lt;P&gt;I have removed the columns, and this is my query:&lt;BR /&gt;
    SELECT ApplicationName, BigintData1, BigintData2, CPU, ClientProcessID, ColumnPermissions, DBUserName, DatabaseID, DatabaseName, Duration, EndTime, Error, EventClass, EventSequence, EventSubClass, FileName, GUID, GroupID, Handle, HostName, IndexID, IntegerData, IntegerData2, IsSystem, LineNumber, LinkedServerName, LoginName, MethodName, Mode, NTDomainName, NTUserName, NestLevel, ObjectID, ObjectID2, ObjectName, ObjectType, Offset, OwnerID, OwnerName, ParentName, Permissions, ProviderName, Reads, RequestID, RoleName, RowCounts, SPID, ServerName, SessionLoginName, Severity, SourceDatabaseID, StartTime, State, Success, TargetLoginName, TargetUserName, TextData, TransactionID, Type, Writes, XactSequence&lt;BR /&gt;
    FROM fn_trace_gettable('C:\\Program Files\\Microsoft SQL Server\\MSSQL11.MSSQLSERVER\\MSSQL\\Log\\log.trc',default) &lt;BR /&gt;
    WHERE StartTime &amp;gt; ? &lt;BR /&gt;
    ORDER BY StartTime ASC&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:40:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-DB-Connect-Checkpoint-Set-To-Null/m-p/340808#M41101</guid>
      <dc:creator>yujietay</dc:creator>
      <dc:date>2020-09-29T17:40:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB Connect -- Checkpoint Set To Null</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-DB-Connect-Checkpoint-Set-To-Null/m-p/340809#M41102</link>
      <description>&lt;P&gt;What if I &lt;EM&gt;want&lt;/EM&gt; to index the column containing the binary data?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2019 18:02:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-DB-Connect-Checkpoint-Set-To-Null/m-p/340809#M41102</guid>
      <dc:creator>nick405060</dc:creator>
      <dc:date>2019-10-09T18:02:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB Connect -- Checkpoint Set To Null</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-DB-Connect-Checkpoint-Set-To-Null/m-p/340810#M41103</link>
      <description>&lt;P&gt;I've been told if this is the case... #cribl&lt;/P&gt;</description>
      <pubDate>Thu, 10 Oct 2019 19:42:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-DB-Connect-Checkpoint-Set-To-Null/m-p/340810#M41103</guid>
      <dc:creator>nick405060</dc:creator>
      <dc:date>2019-10-10T19:42:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB Connect -- Checkpoint Set To Null</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-DB-Connect-Checkpoint-Set-To-Null/m-p/340811#M41104</link>
      <description>&lt;P&gt;Or do this &lt;A href="https://answers.splunk.com/answers/775568/can-splunk-index-gzipd-xmls-from-a-sql-database.html"&gt;https://answers.splunk.com/answers/775568/can-splunk-index-gzipd-xmls-from-a-sql-database.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Oct 2019 19:42:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-DB-Connect-Checkpoint-Set-To-Null/m-p/340811#M41104</guid>
      <dc:creator>nick405060</dc:creator>
      <dc:date>2019-10-10T19:42:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB Connect -- Checkpoint Set To Null</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-DB-Connect-Checkpoint-Set-To-Null/m-p/701342#M81147</link>
      <description>&lt;P&gt;I ran into this issue today and came upon this post. The error I was getting was "&lt;SPAN&gt;&lt;SPAN class=""&gt;Non-Displayable Column Type BINARY" for several columns in my select query. As it turns out, you can modify your select query to cast columns as different types in MySQL, which I did and it solved my issue&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;SELECT&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;CAST(field_name AS CHAR) AS field_name,&lt;BR /&gt;FROM&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;table_name&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I hope this is helpful to anyone else who encounters the same issue.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2024 18:43:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-DB-Connect-Checkpoint-Set-To-Null/m-p/701342#M81147</guid>
      <dc:creator>jplasencia</dc:creator>
      <dc:date>2024-10-08T18:43:38Z</dc:date>
    </item>
  </channel>
</rss>

