Deployment Architecture

Bulk loading DB_inputs for DBConnect - with rising column mode

kozanic_FF
Path Finder

Just wondering if there is anyone out there that has successfully managed to add in multiple new inputs to DBconnect when using Rising Column mode??

I have been attempting to do this today without much success.

Editing the db_inputs.conf file is OK, and the new inputs will show up in DBConnect, but even if I add in a corresponding file to hold the rising column value (even tried copying and editing an existing one), DBConnect complains saying "Error(s) occur when reading checkpoint"

I have multiple instances that I need to update, each with up to 30 inputs that need to be configured - I'm hoping there is a way that I can do this without having to edit each input to update the rising column value.

Appreciate any tips / advise people can offer.

Tags (2)
0 Karma

ianhar
New Member

I'm seeing this error too. My new inputs are not getting data after they're configured.

0 Karma

kozanic_FF
Path Finder

Hi @ianhar ,

Are you using WIndows box?

If so - check the permissions on the below folder:
?\Splunk\var\lib\splunk\modinputs\server\splunk_app_db_connect.

I have noticed that for some reason in windows environment - when you first go to this folder, it will say you don't have access and prompt you to gain access. For some reason - doing this updates the permissions for Splunk user and prevents it from being able to write to that directory.

I was having issues whereby SplunkDB was not able to update the files and kept ingesting duplicate data.

I have not re-tested doing the bulk updating of the checkpoint files since making this discovery - but it's possible it could be a related issue.

0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...