All Apps and Add-ons

Why has the Splunk DB Connect 3.1.1 stopped sending data to indexers?

Path Finder

I have 4 data inputs built off of a MySQL connection. Two of them work, while the other two don't. I've tried changing the "Max Rows to Retrieve", the "Fetch Size", the "Execution Frequency", the JDBC URL to adjust for the timezone, rebuilding the indexer to another name, disabling and re-enabling, and tried to change things from a batch to a rising input type. Nothing is working. I know the data is there and current, because I can use other tools to extract it. I don't think it's the indexer. This has something to do with how DBX is grabbing the data, but I have no idea what could have changed to just stop the data from coming in. Any help would be appreciated.

0 Karma
1 Solution

Path Finder

I changed the query history to only go back a year and that seemed to open things up.

View solution in original post

0 Karma

Path Finder

I changed the query history to only go back a year and that seemed to open things up.

View solution in original post

0 Karma

Path Finder

Just to add, when I run the same query in another tool, the data is there and current. This has to be in the DB connect config somewhere. The weird thing is that it was working, and now it's not. I noticed I cannot set up a Rising input no matter what I do. So maybe the issue is there.

0 Karma

SplunkTrust
SplunkTrust

Any error in DB connect log files ?

0 Karma

Path Finder

no, nothing. I have a ticket opened with support, but was hoping to see if anyone else had this experience with 3.1.1?

0 Karma

Path Finder

I changed the query history to only go back a year and that seemed to open things up.

0 Karma