All Apps and Add-ons

How can we migrate inputs from DB Connect 3.7 to 3.11?

joshiro
Communicator

Splunk Enterprise 9.0.1.
We upgrade DB Connect from 3.7.0. to 3.11.1 and we started to notice that some inputs were not working.
Also on _internal we found an event that lists inputs that require migration.

INFO
c.s.d.s.m.s.DbInputToModularInputInstanceMigrator - DB Inputs requiring migration: [...]

The actual documentation doesnt say anything about this migration.
https://docs.splunk.com/Documentation/DBX/3.11.1/DeployDBX/MigratefromDBConnectv1

Is there any other documentation on how to migrate to the latest version?

UPDATE:

We found that the cron expression validation changed between versions:
'1/10 * * * *' was a valid expression in 3.7, now its no longer valid. We have to do '1-59/10 * * * *'.

Also we have to disable and then enable the input for it to start working again, changing the cron is not enough.

 

Labels (2)
Tags (1)
1 Solution

joshiro
Communicator

We got lots of inputs, we can try to remake them, but its going to take time. This is the last thing we are trying.

We found that the cron expression validation changed between versions:
'1/10 * * * *' was a valid expression in 3.7, now its no longer valid. We have to do '1-59/10 * * * *'.

Also we have to disable and then enable the input for it to start working again, changing the cron is not enough.

View solution in original post

0 Karma

scelikok
SplunkTrust
SplunkTrust

Very nice to hear you solved and thank you for the information.

 

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

scelikok
SplunkTrust
SplunkTrust

If not too many inputs seem to be migrated, you can copy the query and setting to create new inputs. It maybe a faster solution.

If this reply helps you an upvote and "Accept as Solution" is appreciated.

joshiro
Communicator

We got lots of inputs, we can try to remake them, but its going to take time. This is the last thing we are trying.

We found that the cron expression validation changed between versions:
'1/10 * * * *' was a valid expression in 3.7, now its no longer valid. We have to do '1-59/10 * * * *'.

Also we have to disable and then enable the input for it to start working again, changing the cron is not enough.

0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @joshiro,

You can try below migration script.

https://docs.splunk.com/Documentation/DBX/3.9.0/DeployDBX/MigratefromDBConnectv1#Upgrade_and_migrate... 

If this reply helps you an upvote and "Accept as Solution" is appreciated.

joshiro
Communicator

We already saw that documentation, and we didnt try to migrate that way because it doesnt match our context. We are already on 3.7 and that document is for an upgrade from 2.x to 3.
And we were using DB Connect 3 for a long time without problems, this just happened recently when updating to the latest version, from 3.7.0.

Might check what the upgrade scripts do, and see if they help us in any way.

Thanks.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...