This widget could not be displayed.
  • Getting Data In

    DBConnect Inputs not indexing

    madhav_dholakia
    Contributor

    Hi,

    We are using Splunk Cloud and DBConnect App is installed on IDM. I have noticed that some of the DB Inputs stop indexing data after Splunk Cloud Monthly Maintenance Activity.

    I first observed this on 22nd Dec - DBConnect version was 3.4.2

    DBConnect was upgraded to 3.7.0 on 4th Jan and again after the Splunk Cloud Maintenance Activity on 10th Jan, some of the DB Inputs have stopped indexing data.

    Can someone please suggest if this is an expected behavior for some specific types of DB Inputs (if yes, what?) and/or what logs I could check to analyze this issue further?

    We are using MySQL and SQL Server DB Inputs.

    Thank you very much.

    Regards,

    Madhav

    Labels (1)
    0 Karma

    isoutamo
    SplunkTrust
    SplunkTrust

    Hi

    definitely this is not a expected behaviour.

    I have noticed same kind of behaviour on OnPrem side in HFs where we have DBX installed. After update, it sometimes stop to working with rising type inputs. At least until now we have fixed those to release checkpoint and then Excecute SQL -> Next -> Save (or what was the final button?).

    r. Ismo

    madhav_dholakia
    Contributor

    thanks @isoutamo - I have observed the same, it works after manual update. I have now also disabled a large number of unused inputs as well so should be better during the next maintenance window. Thank you.

    0 Karma
    Get Updates on the Splunk Community!

    Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

    WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

    Industry Solutions for Supply Chain and OT, Amazon Use Cases, Plus More New Articles ...

    Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

    Enterprise Security Content Update (ESCU) | New Releases

    In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...