I use Splunk Enterprise 6.3.3 (I also tried before with the Splunk Enterprise 6.4) with the app Splunk DB Connect 2.2.0 (I also tried with Splunk DB Connect 2.1.3)
It's always the same problem... I can configure easily Splunk DB Connect but I can't find the data ine the "Search & Reporting" window...
I don't know why because I can see the data in Operations/DB Inputs/MyInput/Choose and Preview Table......
In MyInput they say that i'm in "valid connection"...
At the step 4/4 they say "succesfully"
All work but I can searche in "Search & Reporting"
Can you help me please? I don't understand...
Thanx a lot
Do you have a Splunk enterprise license?
What schedule is your DB input set to run at?
I have got Splunk Enterprise, I got it for free and I paid nothing : So I have got the "Enterprise Trial License" :
Thanx for your answer!
Hi ryanoconnor, Hi yzimmer,
I have the same problem except I'm using the Enterprise test/dev license. Does the DBConnect not work with this license as well?
Thanks in advance.
Unfortunately according to the documentation for DB Connect:
"Splunk DB Connect has not been tested and is not supported with Splunk Cloud, Splunk Free, or Splunk Light."
Do you mean that Enterprise trial license is the same as Splunk Cloud, Splunk Free, or Splunk Light?
Correct, an enterprise Trial license is Splunk Free
Hi, would be nice to know what your SPL-Command looks like.
Have you created an extra index and/or sourcetype for the DBConnect Data? Make sure you are searching against this specific index. (index= .... ).
If your index is not searched by default for the admin role you will get no results by simply doing [sourcetype=xxxx] or stuff like this.
My Splunk Command to search is just "*".
In DB Input/MyInput/Metadata I just write :
Source : dbx2.log
Sourcetype : dbx2
Index : main
Select Reource Pool : local