Getting Data In

DBConnect input error: No output.format defined for stanza

pembleton
Path Finder

Hello,
I have been using the DBConnect app for splunk for a few weeks, indexing just fine. The problem came up last week, when I noticed events were not up to date.
I checked dbx.log for errors and found the following error for all inputs:

Error:Scheduler - Error while reading
stanza=[dbmon-tail://DatabaseName/InputName]:
com.splunk.config.SplunkConfigurationException: No output.format defined for stanza.

This error occurs even though output.format=kv EXISTS in the stanza in inputs.conf!
I tried restarting Splunk unsuccessfully.
When I used the CLI command:
splunk.exe cmd btool inputs list dbmon-tail://DatabaseName/InputName
the output showed me that all inputs are automatically disabled (disable=1).

How can I prevent this from happenning?

Help please!

0 Karma

lukejadamec
Super Champion

Check for a conflicting inputs.conf file.

Changes to inputs.conf will be made in the app that initiated the change, so if you enter manager from launcher and make a change to a dbx input the stanza will be written to launcher/local/inputs.conf, but if you change it from db connect it will go to dbx/local/inputs.conf.

0 Karma

lukejadamec
Super Champion

Did you restart splunk?

0 Karma

wbfoxii
Communicator

Having the same problem. I looked and indeed there was a stanza in the launcher/local/ directory. I deleted it and then used the DBX app to disable/enable. Still getting the same error. Checked "btool inputs list" and I don't see a conflict.

0 Karma
Get Updates on the Splunk Community!

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

[Coming Soon] Splunk Observability Cloud - Enhanced navigation with a modern look and ...

We are excited to introduce our enhanced UI that brings together AppDynamics and Splunk Observability. This is ...

Splunk Smartness with Patrick Tatro | Episode 4

Welcome to another episode of "Splunk Smartness," where we explore how Splunk Education can revolutionize your ...