All Apps and Add-ons

Splunk DB Connect: Data not indexing

behudelson
Path Finder

Hello, I have a test server and I am trying to use DBConnect to index some SQL data.

Everything appears to be configured appropriately.
In the input configuration screen, my search returns results. I've attached an image of the edit input screen.

I am running DB Connect version 3.1.4 on Splunk Enterprise 7.0.3 with a dev/test license.
Thank you for any help you can provide!

alt text

1 Solution

dhirendra761
Contributor

Hi @behudelson ,

I got this issue and it's related to HEC (HTTP Event Collector) Error, DB Connect injects data in Splunk using HEC. Unfortunately, this problem will occur only with MS server and DB Connect v 3.1.3.

To resolve this issue, you need to uninstall DBConnect v3.1.3 and Install DBConnect v3.1.2.

Thanks.
Dhirendra

View solution in original post

behudelson
Path Finder

Hi @dhirendra761, Thanks for responding. MS Server 2016.

0 Karma

dhirendra761
Contributor

Hi @behudelson Install DBConnect v 3.1.2 and then check. Please share email ID if you want DBConnect v 3.1.2 app.

0 Karma

danielsamp
Engager

Hello @dhirendra761,

could you please also provide me the DBConnect v.3.1.2.
I think I've got the same issue.
Thanks a lot for the help!

Best
Daniel

0 Karma

danielsamp
Engager

@dhirendra761 it worked.

Many thanks!

0 Karma

thaynaminuzzo
Explorer

Hello @dhirendra761 ,
I'm stucked in this issue with DBConnect too.
Could you please send me the v3.1.2?
Thanks!

0 Karma

matteotrombetta
New Member

Hello @dhirendra761
Could you please also provide me the DBConnect v.3.1.2.
I think I've the same problem, the data is not indexing
Thanks a lot for your time and help!

0 Karma

behudelson
Path Finder

Hi @dhirendra761, -------------- is my email. Thank you!

0 Karma

dhirendra761
Contributor

Shared....

0 Karma

behudelson
Path Finder

Hi @dhirendra761 I may not have a chance to test this out until Thursday, but as soon as I confirm that it works I will accept your answer. Thank you for taking the time to assist me!

0 Karma

dhirendra761
Contributor

Sure.. Thank you @behudelson

0 Karma

behudelson
Path Finder

Hi @dhirendra761 I installed 3.1.2 but it just hands at the Set Up DB Connect. My installation steps were: delete splunk_app_db_connect folder from apps containing 3.1.3. Install 3.1.3 from Manage Apps-> Install app from file.

I also noticed that there is a version 3.1.4. Does it also have the same issue with Server 2016?

0 Karma

dhirendra761
Contributor

Hi @behudelson Did you restart the splunk after removing dbconnect app folder.
Please follow the process below:
1- Remove the splunk_app_db_connect folder from apps
2- Restart the splunk(then it will remove app completely otherwise not)
3- Install DBConnect v3.1.2

Thanks.

dhirendra761
Contributor

I never check for v3.1.4

0 Karma

behudelson
Path Finder

Thanks @dhirendra761. I did not restart after removing the folder. I will give that a shot today. I appreciate your time!!

0 Karma

behudelson
Path Finder

Thanks @dhirendra761! For some reason I needed a fresh installation of Splunk Enterprise in order for 3.1.2 to function, but now everything is good to go. I appreciate your help!

dhirendra761
Contributor

Hi @behudelson ,

I got this issue and it's related to HEC (HTTP Event Collector) Error, DB Connect ingest data in Splunk using HEC. Unfortunalely this problem will occur only with MS server and DB Connect v 3.1.3. refer(https://answers.splunk.com/answers/710632/splunk-dbconnect-is-not-creating-sourcetype.html)

To Reslove this issue, you need to uninstall DBConnect APP 3.1.3 and Install its previous version DBConnect 3.1.2.

Also DBConnect 3.1.2 is not available in SplunkBase. Please share your email ID. I will provide to you.

Thanks.
Dhirendra

0 Karma

MousumiChowdhur
Contributor

Hi @behudelson ,

What's your type of input, batch or rising and how are you deciding your timestamp?

behudelson
Path Finder

Hi @MousumiChowdhury, Thanks for asking. My input is batch and my timestamp is current time. The query takes about 5 seconds to return results from the SQL editor. No template is selected.

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...