All Apps and Add-ons

My events have no host value!

ericlarsen
Path Finder

I'm configuring the DB Connect app (v3.1.1) with the SQL Server TA (v1.3.0) on a Heavy Forwarder (Splunk v6.6.5) in order to pull DMV data from our SQL environment. I'm using the default query templates.

All of the queries return data to the HF. However, 5 of them send their data to the Indexers with no host value (only source and sourcetype). Sample Splunk event:

8/1/18
2:36:48.340 PM

2018-08-01 14:36:48.340, object_name="MSSQL$ABCQ1:Memory Broker Clerks ", counter_name="Pressure evictions (pages/sec) ", instance_name="Column store object pool ", cntr_value="0", cntr_type="272696576", max_connection="32767", DatabaseName="master", ServerName="SRVSQLVQ4\ABCQ1"
source = sys.dm_os_performance_counters sourcetype = mssql:os:dm_os_performance_counters tag = database tag = performance

Has anyone seen this before?
Thanks.

jonathanf_splun
Splunk Employee
Splunk Employee

Did you ever get a solution to this? I just recently set up this TA and while I hadn't pinpointed it to the specific queries you seemed to have identified, I do that that I am only getting a host field from ~90% of my events which is terrible.

0 Karma

jacobpevans
Motivator

I'm not familiar with SQL Server, but you could join to a query similar to this in your db connect inputs to get the hostname (I know, horrible work-around, but we do something similar to get the database instance name):

https://social.msdn.microsoft.com/Forums/officeocs/en-US/6720817d-120f-4099-bf0e-e97fd2e26848/how-to...

Cheers,
Jacob

If you feel this response answered your question, please do not forget to mark it as such. If it did not, but you do have the answer, feel free to answer your own post and accept that as the answer.
0 Karma

DalJeanis
Legend

Have you checked for errors in the logs? for instance, this one ? https://answers.splunk.com/answers/421957/splunk-add-on-for-microsoft-sql-server-the-lookup.html

0 Karma

ericlarsen
Path Finder

I did not update $SPLUNK_HOME/etc/apps/Splunk_TA_microsoft-sqlserver/default/transforms.conf because this TA lives on a Heavy Forwarder and that path is correct.

I do not see any errors in the logs, either on the HF or Indexers.

0 Karma

ericlarsen
Path Finder

Note: I tried to manually set the host value via the app configuration, but events still do not have a host in Splunk.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...