All Apps and Add-ons

After upgrading from Splunk DB Connect 1 to version 2, I set up a dbinput, but why does the status change from Enabled to Disabled?


I am attempting to upgrade from Splunk DB Connect v1 to v2, but running into a problem with my first ever input.

Everything looks fine and is set up. Marked as a Valid Connection, and I can save it, but about 1 min later, the status will change from Enabled to Disabled.
Looking at the errors, I see that the function "py_dbinfo:get_catalogs" goes into an error state whenever this happens.

I can query the database fine from within the app. When setting up the input, it shows me the first 100 lines fine. Just seems to error for just about no reason that I can see.


New Member

I am facing the same problem, but not with all the data inputs. If the data input is created with input type=tail then it is facing some problem. Should i check with the query or can i proceed with changing the input.conf files. ,I am facing the same problem, but not with all the data inputs. If i am duplication a data input with input type=tail. Should i try and change the query accordingly or is there any other solution!!

0 Karma


Further to what @jtrujillo said.

Search for db inputs which are getting disabled using the query:

index=_internal sourcetype=dbx2 action=auto_disable_modular_input_due_to_maximum_failed_retries

Once you have the db inputs, go to inputs.conf file and check for those 2 db inputs:

You'll have to change following parameter to ensure its not getting auto disabled.

auto_disable = (true|false)

optional, default is true

If set to true, it would disable this dbinput after max_retries of failed attempts

If you really want, you can change this setting as well.

max_retries =

optional, default number is 6

The max number of failed attemps to execute dbinput before it get disabled

Path Finder

Do the following:

index=_internal sourcetype=dbx2 CRITICAL | top action

And i am betting that you will be getting some sort of error about your data.... I am troubleshooting the same thing right now.

For some reason a dbx2 upgrade (2.2.0) is no longer using my epoch timestamps correctly..... its truncating them in a very weird way....

Just as an FYI you will see that your connection is being disabled automatically using the following search

index=_internal sourcetype=dbx2 action=auto_disable_modular_input_due_to_maximum_failed_retries


This indeed helpful.
How do we stop the connection getting disabled though?

0 Karma


The troubleshooting section of the DB Connect documentation, contains an entry "Database inputs are getting disabled"



Thank you, this is giving me much more to work with.

0 Karma

Path Finder

I've got a SQL server that keeps cutting out for various reasons. The second of jtrujillo's queries above is easily turned into an alert that can tell you when an input has been disabled when something like that occurs. Very helpful!

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...