<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why do inputs from DB Connect absolutely refuse to use my SourceType? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-do-inputs-from-DB-Connect-absolutely-refuse-to-use-my/m-p/632905#M108366</link>
    <description>&lt;P&gt;I'm using DB Connect to input some data from Oracle. I have Splunk installed on a Windows 2016 Server. I cannot seem to get any of my sourcetypes read or used with an input created via DB Connect. No matter what I do, if I run a search from the "Find Events" button of the DB Connect application, then click on "+Extract New Fields", it returns an error:&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;The events associated with this job have no sourcetype information:&amp;nbsp;".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Every. Single. Time.&lt;/P&gt;&lt;P&gt;Sample query:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=thejoy sourcetype=WHYNOT source=JUSTWORKSERIOUSLY OR source=mi_input://JUSTWORKSERIOUSLY&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interestingly enough, if I run the following query I get the EXACT same results:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=thejoy source=JUSTWORKSERIOUSLY OR source=mi_input://JUSTWORKSERIOUSLY&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I get data back from both of these results, but am unable to extract new fields. I have tried doing the following:&lt;/P&gt;&lt;P&gt;*Creating a new Index and assigning it to splunk_app_db_connect&lt;BR /&gt;*Creating a new Index and assigning it to search&lt;BR /&gt;*Creating a new SourceType via Settings &amp;gt; SourceTypes and setting it to Searching &amp;amp; Reporting&lt;BR /&gt;*Creating a new SourceType via Settings &amp;gt; SourceTypes and setting it to Splunk DB Connect&lt;BR /&gt;*Specified the Application for the Data Input to be DB Connect&lt;BR /&gt;*Specified the Application for the Data Input to be the Splunk Search&lt;BR /&gt;*Changing Permissions on DB Connect to allow Everyone to Read/Write&lt;BR /&gt;*Creating a new user and doing all of the above&lt;BR /&gt;*In DB Connect, typing a new value for SourceType that doesn't exist so it gets created automatically&lt;BR /&gt;&lt;BR /&gt;No matter what I try, I just seem to get the same message about no sourcetype information being available for the job.&lt;/P&gt;&lt;P&gt;If I create a new source type via Settings &amp;gt; SourceTypes in the main splunk menu, it doesn't show up in the list for DB Connect (which I understand is a bug). This changes very little, since it's apparently not being used anyways.&lt;/P&gt;&lt;P&gt;If I let DB Connect create a new sourcetype, I do not see it appear in the Settings &amp;gt; SourceTypes menu after the DB Input is created and a successful search is executed.&lt;/P&gt;&lt;P&gt;Also, when I check the props.conf file located in:&lt;BR /&gt;&lt;BR /&gt;C:\Program Files\Splunk\etc\apps\splunk_app_db_connect\local\&lt;/P&gt;&lt;P&gt;my sourcetype is not present at all in the file; it's just an empty file.&lt;/P&gt;&lt;P&gt;I'm just simply at a loss here on why this is happening and what to do. I just want my DB Inputs to recognize my sourcetypes. Ultimately, I want to parse my data as it is going into Splunk using a specific source type. I'm at the point where I'm considering doing a fresh install of Splunk. Any help on this extremely frustrating issue would be greatly appreciated.&lt;/P&gt;</description>
    <pubDate>Thu, 02 Mar 2023 04:16:12 GMT</pubDate>
    <dc:creator>jroeser1404</dc:creator>
    <dc:date>2023-03-02T04:16:12Z</dc:date>
    <item>
      <title>Why do inputs from DB Connect absolutely refuse to use my SourceType?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-do-inputs-from-DB-Connect-absolutely-refuse-to-use-my/m-p/632905#M108366</link>
      <description>&lt;P&gt;I'm using DB Connect to input some data from Oracle. I have Splunk installed on a Windows 2016 Server. I cannot seem to get any of my sourcetypes read or used with an input created via DB Connect. No matter what I do, if I run a search from the "Find Events" button of the DB Connect application, then click on "+Extract New Fields", it returns an error:&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;The events associated with this job have no sourcetype information:&amp;nbsp;".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Every. Single. Time.&lt;/P&gt;&lt;P&gt;Sample query:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=thejoy sourcetype=WHYNOT source=JUSTWORKSERIOUSLY OR source=mi_input://JUSTWORKSERIOUSLY&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interestingly enough, if I run the following query I get the EXACT same results:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=thejoy source=JUSTWORKSERIOUSLY OR source=mi_input://JUSTWORKSERIOUSLY&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I get data back from both of these results, but am unable to extract new fields. I have tried doing the following:&lt;/P&gt;&lt;P&gt;*Creating a new Index and assigning it to splunk_app_db_connect&lt;BR /&gt;*Creating a new Index and assigning it to search&lt;BR /&gt;*Creating a new SourceType via Settings &amp;gt; SourceTypes and setting it to Searching &amp;amp; Reporting&lt;BR /&gt;*Creating a new SourceType via Settings &amp;gt; SourceTypes and setting it to Splunk DB Connect&lt;BR /&gt;*Specified the Application for the Data Input to be DB Connect&lt;BR /&gt;*Specified the Application for the Data Input to be the Splunk Search&lt;BR /&gt;*Changing Permissions on DB Connect to allow Everyone to Read/Write&lt;BR /&gt;*Creating a new user and doing all of the above&lt;BR /&gt;*In DB Connect, typing a new value for SourceType that doesn't exist so it gets created automatically&lt;BR /&gt;&lt;BR /&gt;No matter what I try, I just seem to get the same message about no sourcetype information being available for the job.&lt;/P&gt;&lt;P&gt;If I create a new source type via Settings &amp;gt; SourceTypes in the main splunk menu, it doesn't show up in the list for DB Connect (which I understand is a bug). This changes very little, since it's apparently not being used anyways.&lt;/P&gt;&lt;P&gt;If I let DB Connect create a new sourcetype, I do not see it appear in the Settings &amp;gt; SourceTypes menu after the DB Input is created and a successful search is executed.&lt;/P&gt;&lt;P&gt;Also, when I check the props.conf file located in:&lt;BR /&gt;&lt;BR /&gt;C:\Program Files\Splunk\etc\apps\splunk_app_db_connect\local\&lt;/P&gt;&lt;P&gt;my sourcetype is not present at all in the file; it's just an empty file.&lt;/P&gt;&lt;P&gt;I'm just simply at a loss here on why this is happening and what to do. I just want my DB Inputs to recognize my sourcetypes. Ultimately, I want to parse my data as it is going into Splunk using a specific source type. I'm at the point where I'm considering doing a fresh install of Splunk. Any help on this extremely frustrating issue would be greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 04:16:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-do-inputs-from-DB-Connect-absolutely-refuse-to-use-my/m-p/632905#M108366</guid>
      <dc:creator>jroeser1404</dc:creator>
      <dc:date>2023-03-02T04:16:12Z</dc:date>
    </item>
  </channel>
</rss>

