All Apps and Add-ons

Why is DB Connect incompatible with deployment server?

eregon
Path Finder

Good morning fellow splunkthusiasts,

does anyone know, why DB Connect app is incompatible with deployment server? I (mistakenly) deployed DB Connect 3.1.4 from my deployment server to the heavy forwarder and it seems it works fine. Just after I did so, I noticed the manual says:

DB Connect is incompatible with deployment server. Do not attempt to distribute DB Connect using deployment server.

(see https://docs.splunk.com/Documentation/DBX/3.1.4/DeployDBX/Distributeddeployment)

What can possibly go wrong?

0 Karma
1 Solution

harsmarvania57
Ultra Champion

My assumption is you deployed DB Connect using Deployment server and after deployment you created DB Identities, DB Connections on Heavy Forwarder directly. In this case when you upgrade DB Connect using Deployment Server all config will overwrite on Heavy Forwarder and you will lose all your local DB connect config on Heavy Forwarder.

View solution in original post

0 Karma

eregon
Path Finder

@harsmarvania57 and @skalliger , thank you for your comments, it gives me at least some level of understanding. However now it seems that even upgrading the DB Connect to newer version will be a pain, won't it? Manual only describes the process of migration from version 2 to version 3, but I don't see any instructions to upgrade 3.1.3 (or older) to most recent 3.1.4 without losing the config. Have you ever been into such demand?

0 Karma

harsmarvania57
Ultra Champion

Yes, it requires more steps if you want to upgrade from version 2 to 3. If you want to upgrade from 3.1.3 to 3.1.4 then it is very easy and same process as you upgrade any other add-on.

0 Karma

skalliger
Motivator

As harsmarvania57 wrote, deploying a new app can work just fine. But if you already got an app running, you just should not manage it with the Deployment Server. The reason behind it is that apps like DB Connect store connection state information (e.g. checkpoints) inside their app which would be lost if overwritten by the DS.

Skalli

harsmarvania57
Ultra Champion

Slight correction here Splunk DB Connect 2 stores checkpoint in app itself, however Splunk DB Connect 3 stores checkpoint in $SPLUNK_HOME/var/lib/splunk/modinputs/server/splunk_app_db_connect/

skalliger
Motivator

Ah, I missed that one. Thanks.
I converted the answer to a comment.

0 Karma

harsmarvania57
Ultra Champion

Welcome, no worries 🙂

0 Karma

harsmarvania57
Ultra Champion

My assumption is you deployed DB Connect using Deployment server and after deployment you created DB Identities, DB Connections on Heavy Forwarder directly. In this case when you upgrade DB Connect using Deployment Server all config will overwrite on Heavy Forwarder and you will lose all your local DB connect config on Heavy Forwarder.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...