Deployment Architecture

Bulk loading DB_inputs for DBConnect - with rising column mode

kozanic_FF
Path Finder

Just wondering if there is anyone out there that has successfully managed to add in multiple new inputs to DBconnect when using Rising Column mode??

I have been attempting to do this today without much success.

Editing the db_inputs.conf file is OK, and the new inputs will show up in DBConnect, but even if I add in a corresponding file to hold the rising column value (even tried copying and editing an existing one), DBConnect complains saying "Error(s) occur when reading checkpoint"

I have multiple instances that I need to update, each with up to 30 inputs that need to be configured - I'm hoping there is a way that I can do this without having to edit each input to update the rising column value.

Appreciate any tips / advise people can offer.

Tags (2)
0 Karma

ianhar
New Member

I'm seeing this error too. My new inputs are not getting data after they're configured.

0 Karma

kozanic_FF
Path Finder

Hi @ianhar ,

Are you using WIndows box?

If so - check the permissions on the below folder:
?\Splunk\var\lib\splunk\modinputs\server\splunk_app_db_connect.

I have noticed that for some reason in windows environment - when you first go to this folder, it will say you don't have access and prompt you to gain access. For some reason - doing this updates the permissions for Splunk user and prevents it from being able to write to that directory.

I was having issues whereby SplunkDB was not able to update the files and kept ingesting duplicate data.

I have not re-tested doing the bulk updating of the checkpoint files since making this discovery - but it's possible it could be a related issue.

0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Observability - October 2025

What’s New?  We’re excited to announce the latest enhancements to Splunk Observability Cloud and share what’s ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened Audit Trail v2 wasn’t written in isolation—it was shaped by your voices. In ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...