All Apps and Add-ons

How do I migrate DB inputs from DB Connect V1 to DB connect V3?

zeespl
Explorer

@Niketnilay,

I have DB inputs in DB connect V1 and i want them to moved to DB connect V3.

I checked the db_inputs.conf file but the formatting is totally different. Thats why i can't just copy the entire file as is.

Could you please let me know how I can do it? There are 100+ DB inputs and doing it manually one by one will take huge amount of time.

0 Karma

maciep
Champion

i would suggest doing them one at a time, especially if you have any tails - checkpoints are in a different place and in a different format, and specifying the rising column in the query is different as well. We went through this earlier in the year with around 150 inputs and did them manually.

If they're all snapshot/batch jobs, you could try to script something yourself to create the new format but it may be worth just powering through manually.

We also ingested all of the migrated inputs in our test index initially before actually replacing the v1 version with the v3 version just to be sure the data looked ok.

You may be able to migrate from v1 to v2 and then from v2 to v3, but that seemed a little too adventurous for us...and i'm relatively distrusting of automatic migrations in general, so definitely didn't want to trust 2 of them working correctly.

A couple other things we noticed....if a query has duplicate column names, it may fail in v3. Also, if doing live queries (not inputs), timestamps will be converted to strings when the results are returned - in v1, they were returned as epoch.

Good luck!

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...