All Apps and Add-ons

What is causing Splunk Db connect indexing issue?

Ritu
Explorer

In Splunk db connect some specific data labs are not indexing properly to Splunk means not forwarding its data to Splunk  search head from the databases where as those databases are executing fine what could be the issue is it on server or on Splunk?

Labels (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

can you open more what you have tried and what has happened?

r. Ismo

0 Karma

Ritu
Explorer

There are certain datalabs which are created on a specific server when we run/execute those SQL queries its executing with proper data but the moment we are checking the indexing of that server like, index=dbconnect there are 0 events on the server.
Can it be a server issue somehow?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Have you defined any data inputs or just those dbxqueries?

You need separate data inputs on HF to get data into indexes with DBX on distributed environment. Over that you could also have DBX configured on SH side to do those dbxqueries and monitoring how db inputs are working.

0 Karma

Ritu
Explorer

Yes, those are done still facing issue where as to add in there are distributed environment where different Servers are hosted to different cloud platform and each cloud platform has a DB app configured on it .
So, other cloud platforms we are not facing the issues we are specifically facing issues here.
Could it be the DB servers versions not matching the Splunk DB version ?
Current Splunk DB version is 3.4.2

0 Karma

isoutamo
SplunkTrust
SplunkTrust

If you could do db query on that HF or what ever node your data collection is then also db inputs should work. When you are defining db input you need to create SQL query and if it works then it should also index that data after you have save and enabled it.

You should check that outputs.conf is correct and it send your data to correct environment if/when you have several in use.

0 Karma

Ritu
Explorer

I agree on the point  but seems its not working post saving the SQL queries and executing them.
Could it be the DB servers versions not matching the Splunk DB version ?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Basically everything is possible.

Have you found anything from _internal logs about dbx actions and/or dbx dashboards which could lead you to correct direction?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...