<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Every 1st of month Splunk stops showing data indexed from Splunk DB Connect in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Every-1st-of-month-Splunk-stops-showing-data-indexed-from-Splunk/m-p/21899#M177370</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I have some queries running at Splunk DB Connect, when month changes, like today (from July to August), it always stop showing new indexed data. I am sure that queries are running and events are being indexed (see logs below), because "Summary" dashboard shows it. Every 1st day of month all the charts and dashboards that use data from Splunk DB Connect stop working... every month is the same problem. Anyone know some workaround? I already tried to reinstall Splunk DB Connect without any success.&lt;/P&gt;

&lt;P&gt;dbx.log:&lt;BR /&gt;
2013-08-01 10:11:43.089 monsch1:INFO:Scheduler - Execution of input=[dbmon-dump://PSAV/SYSTEMDELAY  ] finished in duration=0 ms with resultCount=1 success=true continueMonitoring=true&lt;/P&gt;

&lt;P&gt;Summary Dashboard:&lt;BR /&gt;
        sourcetype  Count   Last Update&lt;BR /&gt;
1   SYSTEMDELAY 8,409   Thu Aug 1 10:12:43 2013&lt;/P&gt;</description>
    <pubDate>Thu, 01 Aug 2013 13:16:08 GMT</pubDate>
    <dc:creator>alvaromoraes</dc:creator>
    <dc:date>2013-08-01T13:16:08Z</dc:date>
    <item>
      <title>Every 1st of month Splunk stops showing data indexed from Splunk DB Connect</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Every-1st-of-month-Splunk-stops-showing-data-indexed-from-Splunk/m-p/21899#M177370</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I have some queries running at Splunk DB Connect, when month changes, like today (from July to August), it always stop showing new indexed data. I am sure that queries are running and events are being indexed (see logs below), because "Summary" dashboard shows it. Every 1st day of month all the charts and dashboards that use data from Splunk DB Connect stop working... every month is the same problem. Anyone know some workaround? I already tried to reinstall Splunk DB Connect without any success.&lt;/P&gt;

&lt;P&gt;dbx.log:&lt;BR /&gt;
2013-08-01 10:11:43.089 monsch1:INFO:Scheduler - Execution of input=[dbmon-dump://PSAV/SYSTEMDELAY  ] finished in duration=0 ms with resultCount=1 success=true continueMonitoring=true&lt;/P&gt;

&lt;P&gt;Summary Dashboard:&lt;BR /&gt;
        sourcetype  Count   Last Update&lt;BR /&gt;
1   SYSTEMDELAY 8,409   Thu Aug 1 10:12:43 2013&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2013 13:16:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Every-1st-of-month-Splunk-stops-showing-data-indexed-from-Splunk/m-p/21899#M177370</guid>
      <dc:creator>alvaromoraes</dc:creator>
      <dc:date>2013-08-01T13:16:08Z</dc:date>
    </item>
    <item>
      <title>Re: Every 1st of month Splunk stops showing data indexed from Splunk DB Connect</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Every-1st-of-month-Splunk-stops-showing-data-indexed-from-Splunk/m-p/21900#M177371</link>
      <description>&lt;P&gt;How do you get it working again?&lt;BR /&gt;
Do you get data when you do a simple search?&lt;BR /&gt;
Are the charts and dashboards scheduled?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2013 13:23:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Every-1st-of-month-Splunk-stops-showing-data-indexed-from-Splunk/m-p/21900#M177371</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2013-08-01T13:23:47Z</dc:date>
    </item>
    <item>
      <title>Re: Every 1st of month Splunk stops showing data indexed from Splunk DB Connect</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Every-1st-of-month-Splunk-stops-showing-data-indexed-from-Splunk/m-p/21901#M177372</link>
      <description>&lt;P&gt;1) To get working again I reinstall everything without data backup (with data the problem usually occurs again).&lt;BR /&gt;
2) Even in a simple search the problem is the same, if I run a search of Last 15 minutes no data is found ("No matching events found. Inspect ...").&lt;BR /&gt;
3) No, they aren't.&lt;/P&gt;

&lt;P&gt;Thank you for the answer.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2013 13:30:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Every-1st-of-month-Splunk-stops-showing-data-indexed-from-Splunk/m-p/21901#M177372</guid>
      <dc:creator>alvaromoraes</dc:creator>
      <dc:date>2013-08-01T13:30:09Z</dc:date>
    </item>
    <item>
      <title>Re: Every 1st of month Splunk stops showing data indexed from Splunk DB Connect</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Every-1st-of-month-Splunk-stops-showing-data-indexed-from-Splunk/m-p/21902#M177373</link>
      <description>&lt;P&gt;Is it broken right now?  Or have you reinstalled everything?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2013 13:38:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Every-1st-of-month-Splunk-stops-showing-data-indexed-from-Splunk/m-p/21902#M177373</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2013-08-01T13:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: Every 1st of month Splunk stops showing data indexed from Splunk DB Connect</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Every-1st-of-month-Splunk-stops-showing-data-indexed-from-Splunk/m-p/21903#M177374</link>
      <description>&lt;P&gt;It is broken at moment, I will not try to reinstall until tomorrow.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2013 13:44:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Every-1st-of-month-Splunk-stops-showing-data-indexed-from-Splunk/m-p/21903#M177374</guid>
      <dc:creator>alvaromoraes</dc:creator>
      <dc:date>2013-08-01T13:44:34Z</dc:date>
    </item>
    <item>
      <title>Re: Every 1st of month Splunk stops showing data indexed from Splunk DB Connect</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Every-1st-of-month-Splunk-stops-showing-data-indexed-from-Splunk/m-p/21904#M177375</link>
      <description>&lt;P&gt;Good (for troubleshooting that is).&lt;BR /&gt;
When you run a query from the DBX console, does it timeout or show any errors?&lt;BR /&gt;
Also, what type of database?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2013 13:51:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Every-1st-of-month-Splunk-stops-showing-data-indexed-from-Splunk/m-p/21904#M177375</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2013-08-01T13:51:44Z</dc:date>
    </item>
    <item>
      <title>Re: Every 1st of month Splunk stops showing data indexed from Splunk DB Connect</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Every-1st-of-month-Splunk-stops-showing-data-indexed-from-Splunk/m-p/21905#M177376</link>
      <description>&lt;P&gt;We use an Oracle database.&lt;BR /&gt;
Yes, when I run queries from the DBX  in "Database Query" option everything works ok and fast.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2013 13:57:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Every-1st-of-month-Splunk-stops-showing-data-indexed-from-Splunk/m-p/21905#M177376</guid>
      <dc:creator>alvaromoraes</dc:creator>
      <dc:date>2013-08-01T13:57:53Z</dc:date>
    </item>
    <item>
      <title>Re: Every 1st of month Splunk stops showing data indexed from Splunk DB Connect</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Every-1st-of-month-Splunk-stops-showing-data-indexed-from-Splunk/m-p/21906#M177377</link>
      <description>&lt;P&gt;With a simple search, do a search for the most recent session ID or other unique field that is listed in the dbx query, and search all time.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2013 14:05:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Every-1st-of-month-Splunk-stops-showing-data-indexed-from-Splunk/m-p/21906#M177377</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2013-08-01T14:05:31Z</dc:date>
    </item>
    <item>
      <title>Re: Every 1st of month Splunk stops showing data indexed from Splunk DB Connect</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Every-1st-of-month-Splunk-stops-showing-data-indexed-from-Splunk/m-p/21907#M177378</link>
      <description>&lt;P&gt;Man, what kind of black magic was that? lol&lt;BR /&gt;
Now it works like a charm!&lt;/P&gt;

&lt;P&gt;What I did:&lt;BR /&gt;
1) In Splunk DB Connect I went to "Search" option (not in the Search app).&lt;BR /&gt;
2) Run the search for "All the time" range (without any search string). Some events from today returned \o/&lt;BR /&gt;
3) Verified my dashboards and 1st August is showing ok now!&lt;/P&gt;

&lt;P&gt;lukejadamec, thank you so much for the help! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;If you can, put your answer below so I can vote to this as best answer!&lt;BR /&gt;
:D&lt;/P&gt;

&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2013 14:38:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Every-1st-of-month-Splunk-stops-showing-data-indexed-from-Splunk/m-p/21907#M177378</guid>
      <dc:creator>alvaromoraes</dc:creator>
      <dc:date>2013-08-01T14:38:35Z</dc:date>
    </item>
    <item>
      <title>Re: Every 1st of month Splunk stops showing data indexed from Splunk DB Connect</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Every-1st-of-month-Splunk-stops-showing-data-indexed-from-Splunk/m-p/21908#M177379</link>
      <description>&lt;P&gt;When you run a query from the DBX console, does it timeout or show any errors?&lt;BR /&gt;
Also, what type of database?&lt;BR /&gt;
With a simple search, do a search for the most recent session ID or other unique field that is listed in the dbx query, and search all time.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2013 14:49:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Every-1st-of-month-Splunk-stops-showing-data-indexed-from-Splunk/m-p/21908#M177379</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2013-08-01T14:49:30Z</dc:date>
    </item>
    <item>
      <title>Re: Every 1st of month Splunk stops showing data indexed from Splunk DB Connect</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Every-1st-of-month-Splunk-stops-showing-data-indexed-from-Splunk/m-p/21909#M177380</link>
      <description>&lt;P&gt;Thank you again! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2013 14:52:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Every-1st-of-month-Splunk-stops-showing-data-indexed-from-Splunk/m-p/21909#M177380</guid>
      <dc:creator>alvaromoraes</dc:creator>
      <dc:date>2013-08-01T14:52:00Z</dc:date>
    </item>
  </channel>
</rss>

