All Apps and Add-ons

Splunk DB Connect 2.2.0 - The Configuration works but I can't find data in my "Search & Reporting" window

yzimmer
New Member

Hi!

I use Splunk Enterprise 6.3.3 (I also tried before with the Splunk Enterprise 6.4) with the app Splunk DB Connect 2.2.0 (I also tried with Splunk DB Connect 2.1.3)

It's always the same problem... I can configure easily Splunk DB Connect but I can't find the data ine the "Search & Reporting" window...
I don't know why because I can see the data in Operations/DB Inputs/MyInput/Choose and Preview Table......
alt text

In MyInput they say that i'm in "valid connection"...

At the step 4/4 they say "succesfully"

All work but I can searche in "Search & Reporting"

Can you help me please? I don't understand...

Thanx a lot

0 Karma

ryanoconnor
Builder

Do you have a Splunk enterprise license?

What schedule is your DB input set to run at?

0 Karma

yzimmer
New Member

Hi Ryanoconnor!

I have got Splunk Enterprise, I got it for free and I paid nothing : So I have got the "Enterprise Trial License" :
alt text
link text
http://www.hostingpics.net/viewer.php?id=367085licensing.png

Thanx for your answer!

0 Karma

JoanHorikawa
New Member

Hi ryanoconnor, Hi yzimmer,

I have the same problem except I'm using the Enterprise test/dev license. Does the DBConnect not work with this license as well?

Thanks in advance.

0 Karma

ryanoconnor
Builder

Unfortunately according to the documentation for DB Connect:

"Splunk DB Connect has not been tested and is not supported with Splunk Cloud, Splunk Free, or Splunk Light."

http://docs.splunk.com/Documentation/DBX/2.2.0/DeployDBX/Prerequisites#Splunk_Enterprise

0 Karma

yzimmer
New Member

Do you mean that Enterprise trial license is the same as Splunk Cloud, Splunk Free, or Splunk Light?

Thanx

0 Karma

ryanoconnor
Builder

Correct, an enterprise Trial license is Splunk Free

http://www.splunk.com/en_us/products/splunk-enterprise/free-vs-enterprise.html

0 Karma

TStrauch
Communicator

Hi, would be nice to know what your SPL-Command looks like.

Have you created an extra index and/or sourcetype for the DBConnect Data? Make sure you are searching against this specific index. (index= .... ).
If your index is not searched by default for the admin role you will get no results by simply doing [sourcetype=xxxx] or stuff like this.

0 Karma

yzimmer
New Member

Hi TStrauch!

My Splunk Command to search is just "*".

In DB Input/MyInput/Metadata I just write :
Source : dbx2.log
Sourcetype : dbx2
Index : main
Select Reource Pool : local

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...