All Apps and Add-ons

DB Connect input created does not index however it is showed as healthy

rhyzobium
Observer

Hello

Im trying to create a DB Connect input to log the result of a query inside an index.
The query returns data as I can see when I execute it from Splunk however when I go to the Search I cant find anything in the index that I configured it.

1 - From the "DB Connect Input Health" I see no errors and it shows events from the input I created every x minutes (exactly as I configured it). It also shows this metric that also confirm that there are data been returned in the execution:
DBX - Input Performance - HEC Median Throughput
Search is completed 0.0465 MB

 

2 - From "index=_internal pg6 source="/opt/splunk/var/log/splunk/splunk_app_db_connect_server.log"" I can see that it:
Job 'my_input_name' started
Job 'my_input_name' stopping
Job 'my_input_name' finished with status: COMPLETED

3 - If I search the index I created for it, it is empty.

4 - splunk_app_db_connect 3.9.0


Thanks for any light!

Labels (1)
0 Karma

rhyzobium
Observer

I found the problem 🙂

When you select an index, by default you must select one of the indexes on that instance of Splunk Enterprise. This means that you cannot select an index that you have configured on a search peer but not distributed to the rest of the deployment.

The Indexes I tried to use were from indexer instance, not from the search instance.
Now I created the index in the search instance and I can see my data.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...