- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What is causing Splunk Db connect indexing issue?
In Splunk db connect some specific data labs are not indexing properly to Splunk means not forwarding its data to Splunk search head from the databases where as those databases are executing fine what could be the issue is it on server or on Splunk?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Hi
can you open more what you have tried and what has happened?
r. Ismo
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There are certain datalabs which are created on a specific server when we run/execute those SQL queries its executing with proper data but the moment we are checking the indexing of that server like, index=dbconnect there are 0 events on the server.
Can it be a server issue somehow?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Have you defined any data inputs or just those dbxqueries?
You need separate data inputs on HF to get data into indexes with DBX on distributed environment. Over that you could also have DBX configured on SH side to do those dbxqueries and monitoring how db inputs are working.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, those are done still facing issue where as to add in there are distributed environment where different Servers are hosted to different cloud platform and each cloud platform has a DB app configured on it .
So, other cloud platforms we are not facing the issues we are specifically facing issues here.
Could it be the DB servers versions not matching the Splunk DB version ?
Current Splunk DB version is 3.4.2
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

If you could do db query on that HF or what ever node your data collection is then also db inputs should work. When you are defining db input you need to create SQL query and if it works then it should also index that data after you have save and enabled it.
You should check that outputs.conf is correct and it send your data to correct environment if/when you have several in use.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I agree on the point but seems its not working post saving the SQL queries and executing them.
Could it be the DB servers versions not matching the Splunk DB version ?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Basically everything is possible.
Have you found anything from _internal logs about dbx actions and/or dbx dashboards which could lead you to correct direction?
