<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk connect db not running queries after adding input in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-connect-db-not-running-queries-after-adding-input/m-p/529326#M4151</link>
    <description>&lt;P&gt;The problem began by configuring a DB Connect input on a SHC.&amp;nbsp; Inputs must be installed on a heavy forwarder.&amp;nbsp; See&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/DBX/3.4.0/DeployDBX/Distributeddeployment" target="_blank"&gt;https://docs.splunk.com/Documentation/DBX/3.4.0/DeployDBX/Distributeddeployment&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 13 Nov 2020 16:10:47 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2020-11-13T16:10:47Z</dc:date>
    <item>
      <title>Splunk connect db not running queries after adding input</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-connect-db-not-running-queries-after-adding-input/m-p/529321#M4150</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am on splunk 7.0.2, which is configured in a distributed environment. I installed splunk connect db on a SHC. Then from one of my search heads in the UI, I added my first input. (Note the connection to the db is fine, executing the sql query during setup, yields the expected result.)&lt;/P&gt;&lt;P&gt;However, after adding the input, I can see that connect db does not run the query at all, it ignores the frequency at which the query would run. This is seen in &lt;STRONG&gt;$splunk_home/var/log/splunk/splunk_app_db_connect_server.log&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;The data is not saved at all, I am not sure what am I missing or doing wrong.&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is quite strange is that I cannot find any errors in the log that would help me at least debug why this is being caused, besides this error:&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;ch.qos.logback.core.Appender.error&lt;/STRONG&gt; in&amp;nbsp;&lt;STRONG&gt;splunk_app_db_connect_health_metrics.log&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Note: The SHC is configured properly and is connected with the indexers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have been facing a lot of issues with this.&amp;nbsp; Please help me find the solution or hint me towards how I can debug this.&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Mark&lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2020 15:38:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-connect-db-not-running-queries-after-adding-input/m-p/529321#M4150</guid>
      <dc:creator>markawad</dc:creator>
      <dc:date>2020-11-13T15:38:11Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk connect db not running queries after adding input</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-connect-db-not-running-queries-after-adding-input/m-p/529326#M4151</link>
      <description>&lt;P&gt;The problem began by configuring a DB Connect input on a SHC.&amp;nbsp; Inputs must be installed on a heavy forwarder.&amp;nbsp; See&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/DBX/3.4.0/DeployDBX/Distributeddeployment" target="_blank"&gt;https://docs.splunk.com/Documentation/DBX/3.4.0/DeployDBX/Distributeddeployment&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2020 16:10:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-connect-db-not-running-queries-after-adding-input/m-p/529326#M4151</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-11-13T16:10:47Z</dc:date>
    </item>
  </channel>
</rss>

