<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DB Connect Tail Command not updating in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/DB-Connect-Tail-Command-not-updating/m-p/71584#M180862</link>
    <description>&lt;P&gt;What result do you get when you run the following command (assuming the splunk binary is in $PATH):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;splunk cmd btool inputs list dbmon-tail://DB_Audit/DB_Audit_Tail --debug
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Fri, 21 Jun 2013 23:54:33 GMT</pubDate>
    <dc:creator>ziegfried</dc:creator>
    <dc:date>2013-06-21T23:54:33Z</dc:date>
    <item>
      <title>DB Connect Tail Command not updating</title>
      <link>https://community.splunk.com/t5/Splunk-Search/DB-Connect-Tail-Command-not-updating/m-p/71579#M180857</link>
      <description>&lt;P&gt;I am using a tail db command to pull events from a Oracle database every hour.  I was able to pull in all of the data the first time it ran but I haven't received any new events.  When I looked at the log file I'm receiving the following error message:  &lt;/P&gt;

&lt;P&gt;2013-06-21 10:48:53.060 dbx5648:INFO:DatabaseInfoCommand - Fetching tables for database=DB_Audit&lt;BR /&gt;
2013-06-21 10:49:31.963 dbx9326:INFO:DatabaseInfoCommand - Fetching schemas for database=DB_Audit&lt;BR /&gt;
2013-06-21 10:49:33.123 dbx4360:INFO:DatabaseInfoCommand - Fetching tables for database=DB_Audit&lt;BR /&gt;
2013-06-21 11:21:22.312 monsch1:ERROR:Scheduler - Error while reading stanza=[dbmon-tail://DB_Audit/DB_Audit_Tail]: com.splunk.config.SplunkConfigurationException: No output.format defined for stanza dbmon-tail://DB_Audit/DB_Audit_Tail&lt;BR /&gt;
2013-06-21 11:23:16.671 dbx7573:INFO:DatabaseInfoCommand - Fetching schemas for database=DB_Audit&lt;BR /&gt;
2013-06-21 11:23:18.714 dbx179:INFO:DatabaseInfoCommand - Fetching tables for database=DB_Audit&lt;BR /&gt;
2013-06-21 11:30:16.066 dbx5726:INFO:DatabaseInfoCommand - Fetching schemas for database=DB_Audit&lt;BR /&gt;
2013-06-21 11:30:17.237 dbx373:INFO:DatabaseInfoCommand - Fetching tables for database=DB_Audit&lt;/P&gt;

&lt;P&gt;Any idea what this error is?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:09:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/DB-Connect-Tail-Command-not-updating/m-p/71579#M180857</guid>
      <dc:creator>knewter</dc:creator>
      <dc:date>2020-09-28T14:09:05Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect Tail Command not updating</title>
      <link>https://community.splunk.com/t5/Splunk-Search/DB-Connect-Tail-Command-not-updating/m-p/71580#M180858</link>
      <description>&lt;P&gt;The error suggests that there is no &lt;CODE&gt;output.format&lt;/CODE&gt; in your database input stanza in inputs.conf. This setting is mandatory - you could try to update the input using the UI once and see if that resolves the problem.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2013 17:27:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/DB-Connect-Tail-Command-not-updating/m-p/71580#M180858</guid>
      <dc:creator>ziegfried</dc:creator>
      <dc:date>2013-06-21T17:27:59Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect Tail Command not updating</title>
      <link>https://community.splunk.com/t5/Splunk-Search/DB-Connect-Tail-Command-not-updating/m-p/71581#M180859</link>
      <description>&lt;P&gt;Strange when I look at the inputs.conf file it's there.  Should I just re-save the config file ?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2013 17:32:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/DB-Connect-Tail-Command-not-updating/m-p/71581#M180859</guid>
      <dc:creator>knewter</dc:creator>
      <dc:date>2013-06-21T17:32:49Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect Tail Command not updating</title>
      <link>https://community.splunk.com/t5/Splunk-Search/DB-Connect-Tail-Command-not-updating/m-p/71582#M180860</link>
      <description>&lt;P&gt;That shouldn't be necessary. You can try to restart Splunk in order to force DB Connect to reload the config.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2013 17:34:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/DB-Connect-Tail-Command-not-updating/m-p/71582#M180860</guid>
      <dc:creator>ziegfried</dc:creator>
      <dc:date>2013-06-21T17:34:42Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect Tail Command not updating</title>
      <link>https://community.splunk.com/t5/Splunk-Search/DB-Connect-Tail-Command-not-updating/m-p/71583#M180861</link>
      <description>&lt;P&gt;I've restarted splunk but I'm still receiving the errors.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2013 22:27:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/DB-Connect-Tail-Command-not-updating/m-p/71583#M180861</guid>
      <dc:creator>knewter</dc:creator>
      <dc:date>2013-06-21T22:27:32Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect Tail Command not updating</title>
      <link>https://community.splunk.com/t5/Splunk-Search/DB-Connect-Tail-Command-not-updating/m-p/71584#M180862</link>
      <description>&lt;P&gt;What result do you get when you run the following command (assuming the splunk binary is in $PATH):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;splunk cmd btool inputs list dbmon-tail://DB_Audit/DB_Audit_Tail --debug
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 21 Jun 2013 23:54:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/DB-Connect-Tail-Command-not-updating/m-p/71584#M180862</guid>
      <dc:creator>ziegfried</dc:creator>
      <dc:date>2013-06-21T23:54:33Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect Tail Command not updating</title>
      <link>https://community.splunk.com/t5/Splunk-Search/DB-Connect-Tail-Command-not-updating/m-p/71585#M180863</link>
      <description>&lt;P&gt;I ran the btool command earlier and it shows the output.format in there. &lt;BR /&gt;
/opt/splunk/etc/apps/dbx/local/inputs.conf   output.format = kv&lt;BR /&gt;
/opt/splunk/etc/apps/dbx/local/inputs.conf   output.timestamp = 1&lt;BR /&gt;
/opt/splunk/etc/apps/dbx/local/inputs.conf   output.timestamp.column = created_on&lt;BR /&gt;
/opt/splunk/etc/apps/dbx/local/inputs.conf   output.timestamp.format = MM/dd/yyyy HH:mm:ss.SSS&lt;BR /&gt;
It's like Splunk doesn't see those lines.  The strange thing is it was working a few days ago.&lt;/P&gt;</description>
      <pubDate>Sat, 22 Jun 2013 14:37:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/DB-Connect-Tail-Command-not-updating/m-p/71585#M180863</guid>
      <dc:creator>knewter</dc:creator>
      <dc:date>2013-06-22T14:37:24Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect Tail Command not updating</title>
      <link>https://community.splunk.com/t5/Splunk-Search/DB-Connect-Tail-Command-not-updating/m-p/71586#M180864</link>
      <description>&lt;P&gt;I'm having the same problem as "Knewter". The difference is that I'm trying to read data from MS-SQL. We also tried without the SQL-query, no output-timestamp and different output.formats, all with the same result. The output of "splunk cmd btool inputs list dbmon-tail shows that all settings in the stanza's are read by Splunk correctly.&lt;/P&gt;

&lt;P&gt;Splunk-version=5.0.3&lt;/P&gt;

&lt;P&gt;DB-connect-version=1.0.10&lt;/P&gt;

&lt;P&gt;Environment=Server 2008 R2 Enterprise&lt;/P&gt;

&lt;P&gt;Error-message in "dbx.log"&lt;/P&gt;

&lt;P&gt;2013-07-09 10:46:12.200 monsch1:ERROR:Scheduler - Error while reading stanza=[dbmon-tail://xxxxxxx/xxxxxxx]: com.splunk.config.SplunkConfigurationException: No output.format defined for stanza dbmon-tail://xxxxxxx/xxxxxxx&lt;/P&gt;

&lt;P&gt;SPLUNK_HOME\etc\apps\dbx\local\inputs.conf&lt;/P&gt;

&lt;P&gt;[script://$SPLUNK_HOME\etc\apps\dbx\bin\jbridge_server.py]&lt;/P&gt;

&lt;P&gt;disabled = 0&lt;/P&gt;

&lt;P&gt;[batch://$SPLUNK_HOME\var\spool\dbmon*.dbmonevt]&lt;/P&gt;

&lt;P&gt;crcSalt = &lt;SOURCE&gt;&lt;/SOURCE&gt;&lt;/P&gt;

&lt;P&gt;disabled = 0&lt;/P&gt;

&lt;P&gt;move_policy = sinkhole&lt;/P&gt;

&lt;P&gt;sourcetype = dbmon:spool&lt;/P&gt;

&lt;P&gt;[dbmon-tail://xxxxxxx/xxxxxxx]&lt;/P&gt;

&lt;P&gt;host = xxxxxxx&lt;/P&gt;

&lt;P&gt;index = owa&lt;/P&gt;

&lt;P&gt;interval = 300&lt;/P&gt;

&lt;P&gt;output.format = kv&lt;/P&gt;

&lt;P&gt;output.timestamp = 1&lt;/P&gt;

&lt;P&gt;output.timestamp.column = logtime&lt;/P&gt;

&lt;P&gt;query = select    dbo.xxxxxxx(ClientIP), ClientUserName,logtime,uri from dbo.xxxxxxxxxxxx where  ClientUserName &lt;BR /&gt;
like '%LDAP%' and UrlDestHost LIKE '%mxs%'&lt;/P&gt;

&lt;P&gt;sourcetype = OWA&lt;/P&gt;

&lt;P&gt;tail.rising.column = logtime&lt;/P&gt;

&lt;P&gt;table = dbo.xxxxxxxxxxxx&lt;/P&gt;

&lt;P&gt;output.timestamp.format = yyyy-MM-dd HH:mm:ss.SSS&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:17:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/DB-Connect-Tail-Command-not-updating/m-p/71586#M180864</guid>
      <dc:creator>rschutt</dc:creator>
      <dc:date>2020-09-28T14:17:00Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect Tail Command not updating</title>
      <link>https://community.splunk.com/t5/Splunk-Search/DB-Connect-Tail-Command-not-updating/m-p/71587#M180865</link>
      <description>&lt;P&gt;You may need an output.timestamp.parse.format&lt;BR /&gt;
This is from an old post: &lt;A href="http://splunk-base.splunk.com/answers/71485/splunk-db-connect-timestamp-not-working"&gt;http://splunk-base.splunk.com/answers/71485/splunk-db-connect-timestamp-not-working&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;"The output.timestamp.parse.format is detailed in the DBX documentation, but there is no way to set it from the user interface. Once the timestamp was converted to text and both format filters were set to match the output, everything seemed to start working correctly."&lt;/P&gt;

&lt;P&gt;Output.timestamp.parse.format is explained here:   &lt;A href="http://docs.splunk.com/Documentation/DBX/1.0.11/DeployDBX/inputsspec"&gt;http://docs.splunk.com/Documentation/DBX/1.0.11/DeployDBX/inputsspec&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;You also need to watch out for conflicting input.conf files.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2013 01:38:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/DB-Connect-Tail-Command-not-updating/m-p/71587#M180865</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2013-08-07T01:38:49Z</dc:date>
    </item>
  </channel>
</rss>

