Deployment Architecture

Bulk loading DB_inputs for DBConnect - with rising column mode

kozanic_FF
Path Finder

Just wondering if there is anyone out there that has successfully managed to add in multiple new inputs to DBconnect when using Rising Column mode??

I have been attempting to do this today without much success.

Editing the db_inputs.conf file is OK, and the new inputs will show up in DBConnect, but even if I add in a corresponding file to hold the rising column value (even tried copying and editing an existing one), DBConnect complains saying "Error(s) occur when reading checkpoint"

I have multiple instances that I need to update, each with up to 30 inputs that need to be configured - I'm hoping there is a way that I can do this without having to edit each input to update the rising column value.

Appreciate any tips / advise people can offer.

Tags (2)
0 Karma

ianhar
New Member

I'm seeing this error too. My new inputs are not getting data after they're configured.

0 Karma

kozanic_FF
Path Finder

Hi @ianhar ,

Are you using WIndows box?

If so - check the permissions on the below folder:
?\Splunk\var\lib\splunk\modinputs\server\splunk_app_db_connect.

I have noticed that for some reason in windows environment - when you first go to this folder, it will say you don't have access and prompt you to gain access. For some reason - doing this updates the permissions for Splunk user and prevents it from being able to write to that directory.

I was having issues whereby SplunkDB was not able to update the files and kept ingesting duplicate data.

I have not re-tested doing the bulk updating of the checkpoint files since making this discovery - but it's possible it could be a related issue.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...