All Apps and Add-ons

Splunk DB Connect v3.0.1: Enabling/Disabling a Data Lab "Input" via the GUI adds undefined key/value pairs to db_inputs.conf

keithpretz
Engager

Using Splunk DB Connect version 3.0.1, specific key fields and values are added to a locally defined db_inputs.conf file whenever a defined Data Lab "Input" is Enabled or Disabled (from the DB Connect GUI). There is both an "is_template" and "use_json_output" key/value pair that is added to the stanza for the specific "Input" in the db_inputs.conf file. A subsequent restart of Splunk outputs the following errors:

Invalid key in stanza "[Data Lab Input Name]" in /opt/splunk/etc/apps/splunk_app_db_connect/local/db_inputs.conf, line xx: is_template (value: 0).
Invalid key in stanza "[Data Lab Input Name]" in /opt/splunk/etc/apps/splunk_app_db_connect/local/db_inputs.conf, line xx: use_json_output (value: 0).

Is this a bug (i.e. why does the enable/disable action cause invalid key values to be created in db_inputs.conf)?

agarws8
New Member

I am getting the same error with Splunk DB Connect version 3.0.1 when I upgraded splunk enterprize from 6.5 to 7.0.1

Invalid key in stanza [*******] in /export/splunk/etc/apps/splunk_app_db_connect/local/db_inputs.conf, line 19: is_template (value: 0).
Invalid key in stanza [
****] in /export/splunk/etc/apps/splunk_app_db_connect/local/db_inputs.conf, line 22: use_json_output (value: 0).
Invalid key in stanza [
*****] in /export/splunk/etc/apps/splunk_app_db_connect/local/db_inputs.conf, line 40: is_template (value: 0).
Invalid key in stanza [
*******] in /export/splunk/etc/apps/splunk_app_db_connect/local/db_inputs.conf, line 43: use_json_output (value: 0).

Any help on how this was taken care of!

0 Karma
Get Updates on the Splunk Community!

Understanding Generative AI Techniques and Their Application in Cybersecurity

Watch On-Demand Artificial intelligence is the talk of the town nowadays, with industries of all kinds ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Using the Splunk Threat Research Team’s Latest Security Content

REGISTER HERE Tech Talk | Security Edition Did you know the Splunk Threat Research Team regularly releases ...