All Apps and Add-ons

What is causing Splunk Db connect indexing issue?

Ritu
Explorer

In Splunk db connect some specific data labs are not indexing properly to Splunk means not forwarding its data to Splunk  search head from the databases where as those databases are executing fine what could be the issue is it on server or on Splunk?

Labels (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

can you open more what you have tried and what has happened?

r. Ismo

0 Karma

Ritu
Explorer

There are certain datalabs which are created on a specific server when we run/execute those SQL queries its executing with proper data but the moment we are checking the indexing of that server like, index=dbconnect there are 0 events on the server.
Can it be a server issue somehow?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Have you defined any data inputs or just those dbxqueries?

You need separate data inputs on HF to get data into indexes with DBX on distributed environment. Over that you could also have DBX configured on SH side to do those dbxqueries and monitoring how db inputs are working.

0 Karma

Ritu
Explorer

Yes, those are done still facing issue where as to add in there are distributed environment where different Servers are hosted to different cloud platform and each cloud platform has a DB app configured on it .
So, other cloud platforms we are not facing the issues we are specifically facing issues here.
Could it be the DB servers versions not matching the Splunk DB version ?
Current Splunk DB version is 3.4.2

0 Karma

isoutamo
SplunkTrust
SplunkTrust

If you could do db query on that HF or what ever node your data collection is then also db inputs should work. When you are defining db input you need to create SQL query and if it works then it should also index that data after you have save and enabled it.

You should check that outputs.conf is correct and it send your data to correct environment if/when you have several in use.

0 Karma

Ritu
Explorer

I agree on the point  but seems its not working post saving the SQL queries and executing them.
Could it be the DB servers versions not matching the Splunk DB version ?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Basically everything is possible.

Have you found anything from _internal logs about dbx actions and/or dbx dashboards which could lead you to correct direction?

0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...