All Apps and Add-ons

Splunk DB Connect 2.2.0 - The Configuration works but I can't find data in my "Search & Reporting" window

yzimmer
New Member

Hi!

I use Splunk Enterprise 6.3.3 (I also tried before with the Splunk Enterprise 6.4) with the app Splunk DB Connect 2.2.0 (I also tried with Splunk DB Connect 2.1.3)

It's always the same problem... I can configure easily Splunk DB Connect but I can't find the data ine the "Search & Reporting" window...
I don't know why because I can see the data in Operations/DB Inputs/MyInput/Choose and Preview Table......
alt text

In MyInput they say that i'm in "valid connection"...

At the step 4/4 they say "succesfully"

All work but I can searche in "Search & Reporting"

Can you help me please? I don't understand...

Thanx a lot

0 Karma

ryanoconnor
Builder

Do you have a Splunk enterprise license?

What schedule is your DB input set to run at?

0 Karma

yzimmer
New Member

Hi Ryanoconnor!

I have got Splunk Enterprise, I got it for free and I paid nothing : So I have got the "Enterprise Trial License" :
alt text
link text
http://www.hostingpics.net/viewer.php?id=367085licensing.png

Thanx for your answer!

0 Karma

JoanHorikawa
New Member

Hi ryanoconnor, Hi yzimmer,

I have the same problem except I'm using the Enterprise test/dev license. Does the DBConnect not work with this license as well?

Thanks in advance.

0 Karma

ryanoconnor
Builder

Unfortunately according to the documentation for DB Connect:

"Splunk DB Connect has not been tested and is not supported with Splunk Cloud, Splunk Free, or Splunk Light."

http://docs.splunk.com/Documentation/DBX/2.2.0/DeployDBX/Prerequisites#Splunk_Enterprise

0 Karma

yzimmer
New Member

Do you mean that Enterprise trial license is the same as Splunk Cloud, Splunk Free, or Splunk Light?

Thanx

0 Karma

ryanoconnor
Builder

Correct, an enterprise Trial license is Splunk Free

http://www.splunk.com/en_us/products/splunk-enterprise/free-vs-enterprise.html

0 Karma

TStrauch
Communicator

Hi, would be nice to know what your SPL-Command looks like.

Have you created an extra index and/or sourcetype for the DBConnect Data? Make sure you are searching against this specific index. (index= .... ).
If your index is not searched by default for the admin role you will get no results by simply doing [sourcetype=xxxx] or stuff like this.

0 Karma

yzimmer
New Member

Hi TStrauch!

My Splunk Command to search is just "*".

In DB Input/MyInput/Metadata I just write :
Source : dbx2.log
Sourcetype : dbx2
Index : main
Select Reource Pool : local

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...