Getting Data In

Db connect HTTP 400 Error

Nawab
Communicator

I am getting below error on my dbconnect, every thing was working fine

HTTP Error 400, HEC response body: {"text":"Invalid data format","code":6,"invalid-event-number":15}, trace: HttpResponseProxy{HTTP/1.1 400 Bad Request [Date: Mon, 29 Sep 2025 10:35:01 GMT, Content-Type: application/json; charset=UTF-8, X-Content-Type-Options: nosniff, Content-Length: 65, Vary: Authorization, Connection: Keep-Alive, X-Frame-Options: SAMEORIGIN, Server: Splunkd] ResponseEntityProxy{[Content-Type: application/json; charset=UTF-8,Content-Length: 65,Chunked: false]}}

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Can you tell more about this?

  • Where you are getting this?
  • What you have actually try/done?
  • What is your environment?
  • What DB you have?
  • What are your versions (splunk, dbx, jdbc drivers/packages, OS, target db etc.)
  • Is this db_input or something else?
  • Or are you initially configure your DB Connection to source DB?
0 Karma

Nawab
Communicator

no we haven't changed anything on our query

0 Karma

PrewinThomas
Motivator

@Nawab 

Have you modified any of your query? Can you specify more details.

The error highlights here can be of multiple reasons 

{"text":"Invalid data format","code":6,"invalid-event-number":15}


Regards,
Prewin
If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...