<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DB Connect: I don't see any data after adding my database input in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/DB-Connect-I-don-t-see-any-data-after-adding-my-database-input/m-p/132314#M184587</link>
    <description>&lt;P&gt;If you want to create a index  as "input1" you have to create it in indexes.conf. More details here&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.3/admin/Indexesconf"&gt;http://docs.splunk.com/Documentation/Splunk/6.1.3/admin/Indexesconf&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Sep 2014 20:23:44 GMT</pubDate>
    <dc:creator>pradeepkumarg</dc:creator>
    <dc:date>2014-09-19T20:23:44Z</dc:date>
    <item>
      <title>DB Connect: I don't see any data after adding my database input</title>
      <link>https://community.splunk.com/t5/Splunk-Search/DB-Connect-I-don-t-see-any-data-after-adding-my-database-input/m-p/132303#M184576</link>
      <description>&lt;P&gt;I have defined a database input (dump type) with a simple SQL query and a key-value output format. \&lt;/P&gt;

&lt;P&gt;The "dbx.log" file shows that the query is running without any problems:&lt;/P&gt;

&lt;P&gt;2014-09-19 11:06:08.426 dbx1788:INFO:ExecutionContext - Execution finished in duration=23 ms&lt;BR /&gt;
2014-09-19 11:06:08.427 monsch2:INFO:Scheduler - Execution of input=[dbmon-dump://DB-SERVER/INPUT_SAMPLE_1] finished in duration=22 ms with resultCount=31 success=true continueMonitoring=true&lt;/P&gt;

&lt;P&gt;The Splunk's \spool\dbmon directory has the the right csv_*.dbmonevt files.&lt;/P&gt;

&lt;P&gt;Yet I don't see any data when I try to do the search. Even the source type is not there.&lt;/P&gt;

&lt;P&gt;Am I missing a step in order for this to work?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:38:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/DB-Connect-I-don-t-see-any-data-after-adding-my-database-input/m-p/132303#M184576</guid>
      <dc:creator>abassili</dc:creator>
      <dc:date>2020-09-28T17:38:10Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect: I don't see any data after adding my database input</title>
      <link>https://community.splunk.com/t5/Splunk-Search/DB-Connect-I-don-t-see-any-data-after-adding-my-database-input/m-p/132304#M184577</link>
      <description>&lt;P&gt;Sometime you can get problems with license restrictions or  can define index by default, if so, you could check main index. &lt;BR /&gt;
In addition, check Activity-&amp;gt;jobs.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Sep 2014 16:06:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/DB-Connect-I-don-t-see-any-data-after-adding-my-database-input/m-p/132304#M184577</guid>
      <dc:creator>dimoobraznii</dc:creator>
      <dc:date>2014-09-19T16:06:23Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect: I don't see any data after adding my database input</title>
      <link>https://community.splunk.com/t5/Splunk-Search/DB-Connect-I-don-t-see-any-data-after-adding-my-database-input/m-p/132305#M184578</link>
      <description>&lt;P&gt;Thanks ... I don't see any license alerts or violations and the volume that I have used today is way below the allowed daily volume. I checked "Activity-&amp;gt;jobs", but I could not see any jobs there.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Sep 2014 16:12:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/DB-Connect-I-don-t-see-any-data-after-adding-my-database-input/m-p/132305#M184578</guid>
      <dc:creator>abassili</dc:creator>
      <dc:date>2014-09-19T16:12:14Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect: I don't see any data after adding my database input</title>
      <link>https://community.splunk.com/t5/Splunk-Search/DB-Connect-I-don-t-see-any-data-after-adding-my-database-input/m-p/132306#M184579</link>
      <description>&lt;P&gt;Did you try just with the source filter and see?&lt;/P&gt;

&lt;P&gt;source will be your dbmon input like below&lt;/P&gt;

&lt;P&gt;source=dbmon-tail://*&lt;/P&gt;</description>
      <pubDate>Fri, 19 Sep 2014 17:48:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/DB-Connect-I-don-t-see-any-data-after-adding-my-database-input/m-p/132306#M184579</guid>
      <dc:creator>pradeepkumarg</dc:creator>
      <dc:date>2014-09-19T17:48:00Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect: I don't see any data after adding my database input</title>
      <link>https://community.splunk.com/t5/Splunk-Search/DB-Connect-I-don-t-see-any-data-after-adding-my-database-input/m-p/132307#M184580</link>
      <description>&lt;P&gt;Nothing shows up ...&lt;/P&gt;

&lt;P&gt;Even when I try source=dbmon-tail://...., there is nothing there.&lt;/P&gt;

&lt;P&gt;Splunk does not even recognize this source or sourcetype.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Sep 2014 17:57:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/DB-Connect-I-don-t-see-any-data-after-adding-my-database-input/m-p/132307#M184580</guid>
      <dc:creator>abassili</dc:creator>
      <dc:date>2014-09-19T17:57:14Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect: I don't see any data after adding my database input</title>
      <link>https://community.splunk.com/t5/Splunk-Search/DB-Connect-I-don-t-see-any-data-after-adding-my-database-input/m-p/132308#M184581</link>
      <description>&lt;P&gt;the index that you specified in your database inputs, did you create that index in indexes.conf?&lt;/P&gt;</description>
      <pubDate>Fri, 19 Sep 2014 18:28:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/DB-Connect-I-don-t-see-any-data-after-adding-my-database-input/m-p/132308#M184581</guid>
      <dc:creator>pradeepkumarg</dc:creator>
      <dc:date>2014-09-19T18:28:42Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect: I don't see any data after adding my database input</title>
      <link>https://community.splunk.com/t5/Splunk-Search/DB-Connect-I-don-t-see-any-data-after-adding-my-database-input/m-p/132309#M184582</link>
      <description>&lt;P&gt;I am using the deafult index (Splunk Index: index). I suppose that is already defined.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Sep 2014 18:35:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/DB-Connect-I-don-t-see-any-data-after-adding-my-database-input/m-p/132309#M184582</guid>
      <dc:creator>abassili</dc:creator>
      <dc:date>2014-09-19T18:35:00Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect: I don't see any data after adding my database input</title>
      <link>https://community.splunk.com/t5/Splunk-Search/DB-Connect-I-don-t-see-any-data-after-adding-my-database-input/m-p/132310#M184583</link>
      <description>&lt;P&gt;I don't think there is any index which is called as 'index', you can try 'main' index or create your own index and then configure dbinputs for that index . &lt;/P&gt;</description>
      <pubDate>Fri, 19 Sep 2014 19:15:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/DB-Connect-I-don-t-see-any-data-after-adding-my-database-input/m-p/132310#M184583</guid>
      <dc:creator>pradeepkumarg</dc:creator>
      <dc:date>2014-09-19T19:15:03Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect: I don't see any data after adding my database input</title>
      <link>https://community.splunk.com/t5/Splunk-Search/DB-Connect-I-don-t-see-any-data-after-adding-my-database-input/m-p/132311#M184584</link>
      <description>&lt;P&gt;Thanks, I changed the index to main but sill no luck. Do I need to configure the index I create? Where should I do that? I see the "inputs.conf". Is that the one?&lt;/P&gt;</description>
      <pubDate>Fri, 19 Sep 2014 19:28:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/DB-Connect-I-don-t-see-any-data-after-adding-my-database-input/m-p/132311#M184584</guid>
      <dc:creator>abassili</dc:creator>
      <dc:date>2014-09-19T19:28:18Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect: I don't see any data after adding my database input</title>
      <link>https://community.splunk.com/t5/Splunk-Search/DB-Connect-I-don-t-see-any-data-after-adding-my-database-input/m-p/132312#M184585</link>
      <description>&lt;P&gt;After you change the index to main, you have to make sure new events are returned for your query. I would suggest creating a new database inputs rather than modifying the existing one. &lt;/P&gt;</description>
      <pubDate>Fri, 19 Sep 2014 19:34:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/DB-Connect-I-don-t-see-any-data-after-adding-my-database-input/m-p/132312#M184585</guid>
      <dc:creator>pradeepkumarg</dc:creator>
      <dc:date>2014-09-19T19:34:23Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect: I don't see any data after adding my database input</title>
      <link>https://community.splunk.com/t5/Splunk-Search/DB-Connect-I-don-t-see-any-data-after-adding-my-database-input/m-p/132313#M184586</link>
      <description>&lt;P&gt;Where can I find that file index.conf?&lt;/P&gt;

&lt;P&gt;I have deleted the old database input and created a new one (index = input1).&lt;/P&gt;

&lt;P&gt;Here's the the inputs.conf (I have not changed anything there):&lt;/P&gt;

&lt;H1&gt;Copyright (C) 2005-2014 Splunk Inc. All Rights Reserved.&lt;/H1&gt;

&lt;H1&gt;JBridge Server script&lt;/H1&gt;

&lt;P&gt;[script://./bin/jbridge_server.py]&lt;BR /&gt;
index = input1&lt;BR /&gt;
sourcetype = dbx_jbridge&lt;BR /&gt;
interval = 0&lt;BR /&gt;
disabled = false&lt;BR /&gt;
passAuth = splunk-system-user&lt;BR /&gt;
[script://.\bin\jbridge_server.py]&lt;BR /&gt;
index = input1&lt;BR /&gt;
sourcetype = dbx_jbridge&lt;BR /&gt;
interval = 0&lt;BR /&gt;
disabled = false&lt;BR /&gt;
passAuth = splunk-system-user&lt;/P&gt;

&lt;P&gt;Are there any files that I need to add that index to?&lt;/P&gt;

&lt;P&gt;This is still not working. I got nothing with the search inddex = "input1"&lt;/P&gt;

&lt;P&gt;Thanks a lot for your help. I think I'm getting closer.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:38:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/DB-Connect-I-don-t-see-any-data-after-adding-my-database-input/m-p/132313#M184586</guid>
      <dc:creator>abassili</dc:creator>
      <dc:date>2020-09-28T17:38:32Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect: I don't see any data after adding my database input</title>
      <link>https://community.splunk.com/t5/Splunk-Search/DB-Connect-I-don-t-see-any-data-after-adding-my-database-input/m-p/132314#M184587</link>
      <description>&lt;P&gt;If you want to create a index  as "input1" you have to create it in indexes.conf. More details here&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.3/admin/Indexesconf"&gt;http://docs.splunk.com/Documentation/Splunk/6.1.3/admin/Indexesconf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Sep 2014 20:23:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/DB-Connect-I-don-t-see-any-data-after-adding-my-database-input/m-p/132314#M184587</guid>
      <dc:creator>pradeepkumarg</dc:creator>
      <dc:date>2014-09-19T20:23:44Z</dc:date>
    </item>
  </channel>
</rss>

