All Apps and Add-ons

_internal index not updating, once the Splunk DB Connect 3.1.4 is enabled in Splunk 7.1.1? is there any limitation?

vengat4043
Path Finder

Hi,

In our Production environment we have one Search head and two indexers, all the instance are running in Splunk Version 7.1.1. Recently we faced a issue in one of our indexer like DB_Inputs automatically removed from the Splunk DB Connect App 2.4.0 Version. As our Vendor suggested we upgraded the DB Connect APP to 3.1.4. But now we are facing a different issue, whenever the Splunk DB Connect app 3.1.4 is enabled the Internal logs are not updating? is there any limitation? kindly suggest?

0 Karma

codebuilder
Influencer

My guess is that you are trying to search the _internal index from within the DB Connect app context, which does not (generally) have permissions to do so.

Change your search context to the actual "search" app and it should work for you just fine. Enabling DB Connect does not cause the search head to stop forwarding internal logs.

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

harsmarvania57
Ultra Champion

Hi,

On which instance DB connect in installed, Search Head OR Indexer? There are no such limitation that when you enable DB connect, splunk will stop generating/sending internal logs.

0 Karma
Get Updates on the Splunk Community!

Monitoring Postgres with OpenTelemetry

Behind every business-critical application, you’ll find databases. These behind-the-scenes stores power ...

Mastering Synthetic Browser Testing: Pro Tips to Keep Your Web App Running Smoothly

To start, if you're new to synthetic monitoring, I recommend exploring this synthetic monitoring overview. In ...

Splunk Edge Processor | Popular Use Cases to Get Started with Edge Processor

Splunk Edge Processor offers more efficient, flexible data transformation – helping you reduce noise, control ...