<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk DB Connect - Cannot Delete Data Lab -&amp;gt; inputs in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-Connect-Cannot-Delete-Data-Lab-gt-inputs/m-p/693591#M19787</link>
    <description>&lt;P&gt;My apologies for bringing that old topic up again, but it's the only one about the error message and I stumbled across it while investigating on the same issue (different app version, but not the latest, so it might be fixed).&lt;/P&gt;&lt;P&gt;In summary, I could trace the problem back to local.meta, which listed a user as object owner whose Splunk account had been removed. Solution was to either re-assign the object to a valid user, or remove the owner entry (= assigns it to nobody).&lt;/P&gt;</description>
    <pubDate>Wed, 17 Jul 2024 10:06:51 GMT</pubDate>
    <dc:creator>smichalski</dc:creator>
    <dc:date>2024-07-17T10:06:51Z</dc:date>
    <item>
      <title>Splunk DB Connect - Cannot Delete Data Lab -&gt; inputs</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-Connect-Cannot-Delete-Data-Lab-gt-inputs/m-p/522370#M3634</link>
      <description>&lt;P&gt;I have a Splunk Enterprise Heavy Forwarder which is forwarding SQL Audit Logs by way of the Splunk DB Connect App.&lt;/P&gt;&lt;P&gt;my version of Splunk DB Connect is 3.2.0&lt;/P&gt;&lt;P&gt;(I know this is not the latest version but I am using version 3.2.0 because as soon as we upgrade to 3.4.0 DB Connect breaks completely and won't display anything it the UI).&lt;/P&gt;&lt;P&gt;I am having an issue where I am unable to delete an input which is a clone of another input and not required any more.&lt;/P&gt;&lt;P&gt;the input I want to delete is disabled but the issue happens whether the input is in an enabled or a disabled state.&lt;/P&gt;&lt;P&gt;to delete the input I login to my heavy forwarders Splunk Web Interface&lt;/P&gt;&lt;P&gt;next I select the Splunk DB Connect App from the Apps List on the left&lt;/P&gt;&lt;P&gt;next I select the Data Lab TAB&lt;/P&gt;&lt;P&gt;next I select the inputs option then I click the delete option next to the input I want to delete&lt;/P&gt;&lt;P&gt;I am prompted with the "Are you sure to delete this input?" message and I select OK&lt;/P&gt;&lt;P&gt;at that point I get an error message at the top of the page with the following message:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Splunkd error: HTTP 404 -- Action forbidden.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;my input remains and I am unable to delete it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am an admin and I am also a DB Connect Admin so I have permissions to do whatever I want on this box.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have looked through the splunk_app_db_connect folder in the hope of finding the .conf file where the inputs configurations are stored so that I could manually remove them there. unfortunately I am unable to figure out where these Data Lab -&amp;gt; Inputs are being stored&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I am hoping that someone on here has a deeper understanding of DB Connect and can help me figure out how I can delete my old inputs from DB Connect either by finding the cause of the error and resolving it so it can be done via the GUI or by helping me with finding a way to delete the inputs manually via the file system for the app.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 21:40:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-Connect-Cannot-Delete-Data-Lab-gt-inputs/m-p/522370#M3634</guid>
      <dc:creator>cbwillh</dc:creator>
      <dc:date>2020-09-30T21:40:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB Connect - Cannot Delete Data Lab -&gt; inputs</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-Connect-Cannot-Delete-Data-Lab-gt-inputs/m-p/551606#M5799</link>
      <description>&lt;P&gt;Did you resolve this issue?&amp;nbsp; I'm experiencing the exact same thing.&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 13:50:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-Connect-Cannot-Delete-Data-Lab-gt-inputs/m-p/551606#M5799</guid>
      <dc:creator>ericlarsen</dc:creator>
      <dc:date>2021-05-14T13:50:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB Connect - Cannot Delete Data Lab -&gt; inputs</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-Connect-Cannot-Delete-Data-Lab-gt-inputs/m-p/551615#M5801</link>
      <description>&lt;P&gt;Yes I did figure it out in the end but nobody responded to my issue on here so hence why the solution was not posted.&lt;/P&gt;&lt;P&gt;This is how I manually deleted my Data Lab Inputs from DB Connect&lt;/P&gt;&lt;P&gt;File to edit to manually delete DB Connect Inputs if deleting in GUI fails with error&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;SPLUNK_HOME/etc/apps/search/local/db_inputs.conf&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;NOTE: SPLUNK_HOME = Splunk Home Directory in my case I have a windows Splunk Enterprise server so my full path was&amp;nbsp;C:\Program Files\Splunk\etc\apps\search\local&lt;/P&gt;&lt;P&gt;To manually remove a DB Connect input edit the file above&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;Highlight and delete all related entries for the DB Connect input&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;Example: in my file there was a Test DB so to delete that DB remove the title line and the 6 lines referencing settings for the DB that are immediately below the Title line. See Below&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT color="#0000FF"&gt;[test]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;coldPath = $SPLUNK_DB\test\colddb&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;enableDataIntegrityControl = 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;enableTsidxReduction = 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;homePath = $SPLUNK_DB\test\db&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;maxTotalDataSizeMB = 10240&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#0000FF"&gt;thawedPath = $SPLUNK_DB\test\thaweddb&lt;/FONT&gt;&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;BR /&gt;Save the file&lt;BR /&gt;Restart Splunk&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Confirm in the GUI Console that the Inputs are no longer there&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NOTE: the file above is how I resolved the issue in my environment but just in case the databases are not listed in that file the file below is another location where the DB Connect App Databases are shown so potentially they could be removed there as well.&lt;/P&gt;&lt;P&gt;C:\Program Files\Splunk\etc\apps\splunk_app_db_connect\local\db_inputs.conf&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 15:15:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-Connect-Cannot-Delete-Data-Lab-gt-inputs/m-p/551615#M5801</guid>
      <dc:creator>cbwillh</dc:creator>
      <dc:date>2021-05-14T15:15:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB Connect - Cannot Delete Data Lab -&gt; inputs</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-Connect-Cannot-Delete-Data-Lab-gt-inputs/m-p/693591#M19787</link>
      <description>&lt;P&gt;My apologies for bringing that old topic up again, but it's the only one about the error message and I stumbled across it while investigating on the same issue (different app version, but not the latest, so it might be fixed).&lt;/P&gt;&lt;P&gt;In summary, I could trace the problem back to local.meta, which listed a user as object owner whose Splunk account had been removed. Solution was to either re-assign the object to a valid user, or remove the owner entry (= assigns it to nobody).&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2024 10:06:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-Connect-Cannot-Delete-Data-Lab-gt-inputs/m-p/693591#M19787</guid>
      <dc:creator>smichalski</dc:creator>
      <dc:date>2024-07-17T10:06:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB Connect - Cannot Delete Data Lab -&gt; inputs</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-Connect-Cannot-Delete-Data-Lab-gt-inputs/m-p/693602#M19788</link>
      <description>&lt;P&gt;Hi &lt;SPAN style="background: var(--ck-color-mention-background); color: var(--ck-color-mention-text);"&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/177720"&gt;@smichalski&lt;/a&gt;&lt;/SPAN&gt; ,&lt;/P&gt;
&lt;P&gt;I’m a Community Moderator in the Splunk Community.&lt;/P&gt;
&lt;P&gt;This question was posted 4 years ago, so it might not get the attention you need for your question to be answered. We recommend that you post a new question so that your issue can get the &amp;nbsp;visibility it deserves. To increase your chances of getting help from the community, follow &lt;A href="http://docs.splunk.com/Documentation/Splunkbase/splunkbase/Answers/Questions" target="_blank"&gt;&lt;U&gt;these guidelines&lt;/U&gt;&lt;/A&gt; in the Splunk Answers User Manual when creating your post.&lt;/P&gt;
&lt;P&gt;Thank you!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jul 2024 12:05:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-DB-Connect-Cannot-Delete-Data-Lab-gt-inputs/m-p/693602#M19788</guid>
      <dc:creator>DanielPi</dc:creator>
      <dc:date>2024-07-17T12:05:12Z</dc:date>
    </item>
  </channel>
</rss>

