All Apps and Add-ons

Splunk DB Connect: Data not indexing

behudelson
Path Finder

Hello, I have a test server and I am trying to use DBConnect to index some SQL data.

Everything appears to be configured appropriately.
In the input configuration screen, my search returns results. I've attached an image of the edit input screen.

I am running DB Connect version 3.1.4 on Splunk Enterprise 7.0.3 with a dev/test license.
Thank you for any help you can provide!

alt text

1 Solution

dhirendra761
Contributor

Hi @behudelson ,

I got this issue and it's related to HEC (HTTP Event Collector) Error, DB Connect injects data in Splunk using HEC. Unfortunately, this problem will occur only with MS server and DB Connect v 3.1.3.

To resolve this issue, you need to uninstall DBConnect v3.1.3 and Install DBConnect v3.1.2.

Thanks.
Dhirendra

View solution in original post

behudelson
Path Finder

Hi @dhirendra761, Thanks for responding. MS Server 2016.

0 Karma

dhirendra761
Contributor

Hi @behudelson Install DBConnect v 3.1.2 and then check. Please share email ID if you want DBConnect v 3.1.2 app.

0 Karma

danielsamp
Engager

Hello @dhirendra761,

could you please also provide me the DBConnect v.3.1.2.
I think I've got the same issue.
Thanks a lot for the help!

Best
Daniel

0 Karma

danielsamp
Engager

@dhirendra761 it worked.

Many thanks!

0 Karma

thaynaminuzzo
Explorer

Hello @dhirendra761 ,
I'm stucked in this issue with DBConnect too.
Could you please send me the v3.1.2?
Thanks!

0 Karma

matteotrombetta
New Member

Hello @dhirendra761
Could you please also provide me the DBConnect v.3.1.2.
I think I've the same problem, the data is not indexing
Thanks a lot for your time and help!

0 Karma

behudelson
Path Finder

Hi @dhirendra761, -------------- is my email. Thank you!

0 Karma

dhirendra761
Contributor

Shared....

0 Karma

behudelson
Path Finder

Hi @dhirendra761 I may not have a chance to test this out until Thursday, but as soon as I confirm that it works I will accept your answer. Thank you for taking the time to assist me!

0 Karma

dhirendra761
Contributor

Sure.. Thank you @behudelson

0 Karma

behudelson
Path Finder

Hi @dhirendra761 I installed 3.1.2 but it just hands at the Set Up DB Connect. My installation steps were: delete splunk_app_db_connect folder from apps containing 3.1.3. Install 3.1.3 from Manage Apps-> Install app from file.

I also noticed that there is a version 3.1.4. Does it also have the same issue with Server 2016?

0 Karma

dhirendra761
Contributor

Hi @behudelson Did you restart the splunk after removing dbconnect app folder.
Please follow the process below:
1- Remove the splunk_app_db_connect folder from apps
2- Restart the splunk(then it will remove app completely otherwise not)
3- Install DBConnect v3.1.2

Thanks.

dhirendra761
Contributor

I never check for v3.1.4

0 Karma

behudelson
Path Finder

Thanks @dhirendra761. I did not restart after removing the folder. I will give that a shot today. I appreciate your time!!

0 Karma

behudelson
Path Finder

Thanks @dhirendra761! For some reason I needed a fresh installation of Splunk Enterprise in order for 3.1.2 to function, but now everything is good to go. I appreciate your help!

dhirendra761
Contributor

Hi @behudelson ,

I got this issue and it's related to HEC (HTTP Event Collector) Error, DB Connect ingest data in Splunk using HEC. Unfortunalely this problem will occur only with MS server and DB Connect v 3.1.3. refer(https://answers.splunk.com/answers/710632/splunk-dbconnect-is-not-creating-sourcetype.html)

To Reslove this issue, you need to uninstall DBConnect APP 3.1.3 and Install its previous version DBConnect 3.1.2.

Also DBConnect 3.1.2 is not available in SplunkBase. Please share your email ID. I will provide to you.

Thanks.
Dhirendra

0 Karma

MousumiChowdhur
Contributor

Hi @behudelson ,

What's your type of input, batch or rising and how are you deciding your timestamp?

behudelson
Path Finder

Hi @MousumiChowdhury, Thanks for asking. My input is batch and my timestamp is current time. The query takes about 5 seconds to return results from the SQL editor. No template is selected.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...