Recently that made the update Splunk App DB Connect V2 to version 2.2.0. App really has improved with each new update. However, we have identified in this latest version that whenever the instance of Splunk lost the connection to the database (Oracle), the DB inputs are automatically disabled. As our Splunk instance is in a different Data Center database instance, this connection loss may occur several times throughout the month.
After much analysis, we identified that as from version 2.1.2 was implemented the command "autodisable = true" by default in inputs.conf. We managed to solve the problem by entering the command "autodisable = false" the bottom of each stanza in the inputs.conf. Example: