I work in a dynamic environment and often servers will get restarted for various reasons, updates for example..
Often I'll miss these events because I'm not on-call or nobody tells me. What happens is Splunk DB Connect disables all the inputs for that server and never tries to re-enable them.
So that data stops flowing into Splunk until someone manually re-enables the inputs for the servers in question.
My question is: Is there any way to have auto-retry logic? Or is there something I can use to monitor for inputs that get disabled? Right now I simply can't trust the data going into it because of this.
Hi @johnpof
There's a previous Answers post similar to this topic with an answer that suggests disabling the auto_disable setting in inputs.conf. That might solve your issue:
https://answers.splunk.com/answers/438527/how-to-prevent-splunk-db-connect-2-from-disabling.html