All Apps and Add-ons

Splunk DB Connect input is not querying from MS SQL Server

sreejusreekumar
New Member

Hi,

I'm trying to index database table data to Splunk Enterprise Trial version using Splunk DB Connect 3. Data inputs were created with rising column and scheduled to query table every 5 minutes.

2019-08-05 12:05:24.137 +1000 [dw-53 - PUT /api/inputs/APIQADBLOG] INFO com.splunk.dbx.server.task.DefaultTaskService - action=add_task_to_scheduler task=com.splunk.dbx.server.dbinput.task.DbInputTask@d0d8abbe cron=0 * /5 ? * *

Noticed table data is not getting indexed and checkpoint file is getting deleted based on below logs. Actually the checkpoint log is available physically in machine. Can anyone help

05/08/2019
13:59:59.784

2019-08-05 13:59:59.784 +1000 [Checkpoint-Cleaner-0] INFO c.s.d.s.m.CheckpointCleaner$CheckpointCleanerTask - action=checkpoint_files_to_be_deleted []

source = C:\Program Files\Splunk\var\log\splunk\splunk_app_db_connect_server.log

sourcetype = dbx_server


05/08/2019
13:59:59.784

2019-08-05 13:59:59.784 +1000 [Checkpoint-Cleaner-0] INFO c.s.d.s.m.CheckpointCleaner$CheckpointCleanerTask - action=start_checkpoint_cleaner_task

source = C:\Program Files\Splunk\var\log\splunk\splunk_app_db_connect_server.log

sourcetype = dbx_server


05/08/2019
12:59:59.784

2019-08-05 12:59:59.784 +1000 [Checkpoint-Cleaner-0] INFO c.s.d.s.m.CheckpointCleaner$CheckpointCleanerTask - action=checkpoint_files_to_be_deleted []

source = C:\Program Files\Splunk\var\log\splunk\splunk_app_db_connect_server.log

sourcetype = dbx_server


05/08/2019
12:59:59.783

2019-08-05 12:59:59.783 +1000 [Checkpoint-Cleaner-0] INFO c.s.d.s.m.CheckpointCleaner$CheckpointCleanerTask - action=start_checkpoint_cleaner_task

source = C:\Program Files\Splunk\var\log\splunk\splunk_app_db_connect_server.log

sourcetype = dbx_server


05/08/2019
12:05:24.137

2019-08-05 12:05:24.137 +1000 [dw-53 - PUT /api/inputs/APIQADBLOG] INFO org.easybatch.extensions.quartz.JobScheduler - Scheduling job org.easybatch.core.job.BatchJob@599f3565 with cron expression 0 * /5 ? * *

source = C:\Program Files\Splunk\var\log\splunk\splunk_app_db_connect_server.log

sourcetype = dbx_server

0 Karma
Get Updates on the Splunk Community!

Leveraging Detections from the Splunk Threat Research Team & Cisco Talos

  Now On Demand  Stay ahead of today’s evolving threats with the combined power of the Splunk Threat Research ...

New in Splunk Observability Cloud: Automated Archiving for Unused Metrics

Automated Archival is a new capability within Metrics Management; which is a robust usage & cost optimization ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...