All Apps and Add-ons

Splunk DB Connect Inputs not working. What do I specify for source and sourcetype?

vivianlok
New Member

I connected a database through configuration. When I try to add input source and sourcetype, I do not get any results. I even tried creating my own sourcetype.

Here is what the documentation specified:

Source: Optional. The input name will be used if you leave it blank.
Source type: Enter a sourcetype field value for Splunk Enterprise to assign to queried data as it is indexed. Click the field and enter a value, or choose an existing value from the menu that appears.

0 Karma

Kirantcs
Path Finder

Hi it is always best practice to provide sourcetype

Souretype=provide some value through which you can recognize different datas.

source=not necessary,if blank dbconnect takes the input name

host=Can provide your instance name(source of data database name)

0 Karma

darrenfuller
Contributor

In dbx, both source and sourcetype are free text fields which will accept pretty much any value. Along with index, they give a three pronged pointer to find dbx sourced data.

In search, if you can't find your data using
index= source= sourcetype=

Then try:

index=_internal sourcetype=dbx*

And see what kind of errors are being raised by your input.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...