<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Data suddenly stopped indexing data from DB connect app? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Data-suddenly-stopped-indexing-data-from-DB-connect-app/m-p/385721#M46923</link>
    <description>&lt;P&gt;Did you search over &lt;CODE&gt;all time&lt;/CODE&gt; just in case the time stamps are not correct/recognised ?&lt;/P&gt;</description>
    <pubDate>Thu, 15 Nov 2018 03:19:05 GMT</pubDate>
    <dc:creator>MuS</dc:creator>
    <dc:date>2018-11-15T03:19:05Z</dc:date>
    <item>
      <title>Data suddenly stopped indexing data from DB connect app?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Data-suddenly-stopped-indexing-data-from-DB-connect-app/m-p/385718#M46920</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;In DB connect app for one of the connections we are able to see the sql output in the app but it has stopped indexing. We can see the connection name in dbx_audit log but no errors.&lt;/P&gt;

&lt;P&gt;11/15/18&lt;BR /&gt;
12:56:13.938 PM &lt;BR /&gt;
2018-11-15 12:56:13.938 25125@psplunksh03 [main] INFO  com.splunk.dbx.connector.logger.AuditLogger - operation=dbxquery connection_name=OBJPROD stanza_name= state=success sql='select ACTIVE_USERS, LICENSE_COUNT from (select count(&lt;EM&gt;) as Active_Users from users where DATE_INACTIVATE is null and DATE_DISABLE is null) cross join LICENSED_USERS'&lt;BR /&gt;
host =   source =   /opt/splunk/var/log/splunk/splunk_app_db_connect_audit_command.2018-11-15.log sourcetype =  dbx_audit&lt;BR /&gt;
11/15/18&lt;BR /&gt;
12:49:11.195 PM &lt;BR /&gt;
2018-11-15 12:49:11.195 54724@psplunksh03 [main] INFO  com.splunk.dbx.connector.logger.AuditLogger - operation=dbxquery connection_name=OBJPROD stanza_name= state=success sql='select ACTIVE_USERS, LICENSE_COUNT from (select count(&lt;/EM&gt;) as Active_Users from users where DATE_INACTIVATE is null and DATE_DISABLE is null) cross join LICENSED_USERS'&lt;BR /&gt;
host =   source =   /opt/splunk/var/log/splunk/splunk_app_db_connect_audit_command.2018-11-15.log sourcetype =  dbx_audit&lt;BR /&gt;
11/15/18&lt;BR /&gt;
12:41:00.687 PM &lt;BR /&gt;
2018-11-15 12:41:00.687 17855@psplunksh03 [main] INFO  com.splunk.dbx.connector.logger.AuditLogger - operation=dbxquery connection_name=OBJPROD stanza_name= state=success sql='select ACTIVE_USERS, LICENSE_COUNT from (select count(&lt;EM&gt;) as Active_Users from users where DATE_INACTIVATE is null and DATE_DISABLE is null) cross join LICENSED_USERS'&lt;BR /&gt;
host =   source =   /opt/splunk/var/log/splunk/splunk_app_db_connect_audit_command.2018-11-15.log sourcetype =  dbx_audit&lt;BR /&gt;
11/15/18&lt;BR /&gt;
12:34:05.424 PM &lt;BR /&gt;
2018-11-15 12:34:05.424 47505@psplunksh03 [main] INFO  com.splunk.dbx.connector.logger.AuditLogger - operation=dbxquery connection_name=OBJPROD stanza_name= state=success sql='select ACTIVE_USERS, LICENSE_COUNT from (select count(&lt;/EM&gt;) as Active_Users from users where DATE_INACTIVATE is null and DATE_DISABLE is null) cross join LICENSED_USERS'&lt;BR /&gt;
host =   source =   /opt/splunk/var/log/splunk/splunk_app_db_connect_audit_command.2018-11-15.log sourcetype =  dbx_audit&lt;BR /&gt;
11/15/18&lt;BR /&gt;
12:20:21.338 PM &lt;BR /&gt;
2018-11-15 12:20:21.338 46563@psplunksh03 [main] INFO  com.splunk.dbx.connector.logger.AuditLogger - operation=dbxquery connection_name=OBJPROD stanza_name= state=success sql='select ACTIVE_USERS, LICENSE_COUNT from (select count(&lt;EM&gt;) as Active_Users from users where DATE_INACTIVATE is null and DATE_DISABLE is null) cross join LICENSED_USERS'&lt;BR /&gt;
host =   source =   /opt/splunk/var/log/splunk/splunk_app_db_connect_audit_command.2018-11-15.log sourcetype =  dbx_audit&lt;BR /&gt;
11/15/18&lt;BR /&gt;
12:15:07.969 PM &lt;BR /&gt;
2018-11-15 12:15:07.969 22282@psplunksh03 [main] INFO  com.splunk.dbx.connector.logger.AuditLogger - operation=dbxquery connection_name=OBJPROD stanza_name= state=success sql='select ACTIVE_USERS, LICENSE_COUNT from (select count(&lt;/EM&gt;) as Active_Users from users where DATE_INACTIVATE is null and DATE_DISABLE is null) cross join LICENSED_USERS'&lt;BR /&gt;
host =   source =   /opt/splunk/var/log/splunk/splunk_app_db_connect_audit_command.2018-11-15.log sourcetype =  dbx_audit&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 21:59:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Data-suddenly-stopped-indexing-data-from-DB-connect-app/m-p/385718#M46920</guid>
      <dc:creator>ketannagpal</dc:creator>
      <dc:date>2020-09-29T21:59:51Z</dc:date>
    </item>
    <item>
      <title>Re: Data suddenly stopped indexing data from DB connect app?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Data-suddenly-stopped-indexing-data-from-DB-connect-app/m-p/385719#M46921</link>
      <description>&lt;P&gt;Hi ketannagpal,&lt;/P&gt;

&lt;P&gt;a good starting point is the DB connect input health &lt;A href="http://docs.splunk.com/Documentation/DBX/health/DeployDBX/Monitordatabaseconnectionhealth"&gt;http://docs.splunk.com/Documentation/DBX/health/DeployDBX/Monitordatabaseconnectionhealth&lt;/A&gt; it might be your input was disabled by DB connect because of too many errors on it. &lt;/P&gt;

&lt;P&gt;If the input is still enabled, check the troubleshooting section of the docs &lt;A href="http://docs.splunk.com/Documentation/DBX/latest/DeployDBX/Troubleshooting"&gt;http://docs.splunk.com/Documentation/DBX/latest/DeployDBX/Troubleshooting&lt;/A&gt; which provides a lot of useful tips.&lt;/P&gt;

&lt;P&gt;Hope this helps ...&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Thu, 15 Nov 2018 02:49:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Data-suddenly-stopped-indexing-data-from-DB-connect-app/m-p/385719#M46921</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2018-11-15T02:49:20Z</dc:date>
    </item>
    <item>
      <title>Re: Data suddenly stopped indexing data from DB connect app?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Data-suddenly-stopped-indexing-data-from-DB-connect-app/m-p/385720#M46922</link>
      <description>&lt;P&gt;Thanks MuS, I have verified everything in DB connect. This is an issue with one particular connection,In DB connect app everything looks good, but data is not present in indexer. I can also see the sourcetype present in license.log file.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Nov 2018 03:11:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Data-suddenly-stopped-indexing-data-from-DB-connect-app/m-p/385720#M46922</guid>
      <dc:creator>ketannagpal</dc:creator>
      <dc:date>2018-11-15T03:11:54Z</dc:date>
    </item>
    <item>
      <title>Re: Data suddenly stopped indexing data from DB connect app?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Data-suddenly-stopped-indexing-data-from-DB-connect-app/m-p/385721#M46923</link>
      <description>&lt;P&gt;Did you search over &lt;CODE&gt;all time&lt;/CODE&gt; just in case the time stamps are not correct/recognised ?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Nov 2018 03:19:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Data-suddenly-stopped-indexing-data-from-DB-connect-app/m-p/385721#M46923</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2018-11-15T03:19:05Z</dc:date>
    </item>
  </channel>
</rss>

