All Apps and Add-ons

Splunk DB Connect: How to resolve error "Database 'NULL' does not exist"?

sassens1
Path Finder

Hello,

after a while my Splunk DB Connect instance stopped working and I noticed this particular error message:

ERROR ServiceResponder:352 - action=service_responder_responding_error error={}
com.microsoft.sqlserver.jdbc.SQLServerException: Database 'NULL' does not exist. Make sure that the name is entered correctly.
    at com.microsoft.sqlserver.jdbc.SQLServerException.makeFromDatabaseError(SQLServerException.java:216)
    at com.microsoft.sqlserver.jdbc.TDSTokenHandler.onEOF(tdsparser.java:254)
../..

Basically I've checked the config and overwritten it, pure and simple. it immediately started working for few minutes then again the error message.
On the DB server side everything is OK and nothing has changed.

It's like Splunk DB Connect doesn't keep the database name.

Any idea?

0 Karma
1 Solution

sassens1
Path Finder

I've restarted splunk and it seems to have fixed the issue...
So far if any modification is done on the input config, splunk should be restarted I suppose.

View solution in original post

0 Karma

sassens1
Path Finder

I've restarted splunk and it seems to have fixed the issue...
So far if any modification is done on the input config, splunk should be restarted I suppose.

0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

Yes, whenever you make changes to configuration files, you should restart Splunk for those changes to take effect: https://docs.splunk.com/Documentation/Splunk/6.5.1/Admin/Configurationfilechangesthatrequirerestart

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...