All Apps and Add-ons

How can we migrate inputs from DB Connect 3.7 to 3.11?

joshiro
Communicator

Splunk Enterprise 9.0.1.
We upgrade DB Connect from 3.7.0. to 3.11.1 and we started to notice that some inputs were not working.
Also on _internal we found an event that lists inputs that require migration.

INFO
c.s.d.s.m.s.DbInputToModularInputInstanceMigrator - DB Inputs requiring migration: [...]

The actual documentation doesnt say anything about this migration.
https://docs.splunk.com/Documentation/DBX/3.11.1/DeployDBX/MigratefromDBConnectv1

Is there any other documentation on how to migrate to the latest version?

UPDATE:

We found that the cron expression validation changed between versions:
'1/10 * * * *' was a valid expression in 3.7, now its no longer valid. We have to do '1-59/10 * * * *'.

Also we have to disable and then enable the input for it to start working again, changing the cron is not enough.

 

Labels (2)
Tags (1)
1 Solution

joshiro
Communicator

We got lots of inputs, we can try to remake them, but its going to take time. This is the last thing we are trying.

We found that the cron expression validation changed between versions:
'1/10 * * * *' was a valid expression in 3.7, now its no longer valid. We have to do '1-59/10 * * * *'.

Also we have to disable and then enable the input for it to start working again, changing the cron is not enough.

View solution in original post

0 Karma

scelikok
SplunkTrust
SplunkTrust

Very nice to hear you solved and thank you for the information.

 

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

scelikok
SplunkTrust
SplunkTrust

If not too many inputs seem to be migrated, you can copy the query and setting to create new inputs. It maybe a faster solution.

If this reply helps you an upvote and "Accept as Solution" is appreciated.

joshiro
Communicator

We got lots of inputs, we can try to remake them, but its going to take time. This is the last thing we are trying.

We found that the cron expression validation changed between versions:
'1/10 * * * *' was a valid expression in 3.7, now its no longer valid. We have to do '1-59/10 * * * *'.

Also we have to disable and then enable the input for it to start working again, changing the cron is not enough.

0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @joshiro,

You can try below migration script.

https://docs.splunk.com/Documentation/DBX/3.9.0/DeployDBX/MigratefromDBConnectv1#Upgrade_and_migrate... 

If this reply helps you an upvote and "Accept as Solution" is appreciated.

joshiro
Communicator

We already saw that documentation, and we didnt try to migrate that way because it doesnt match our context. We are already on 3.7 and that document is for an upgrade from 2.x to 3.
And we were using DB Connect 3 for a long time without problems, this just happened recently when updating to the latest version, from 3.7.0.

Might check what the upgrade scripts do, and see if they help us in any way.

Thanks.

0 Karma
Get Updates on the Splunk Community!

2024 Splunk Career Impact Survey | Earn a $20 gift card for participating!

Hear ye, hear ye! The time has come again for Splunk's annual Career Impact Survey!  We need your help by ...

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...