Getting Data In

How to ingest MongoDB logs from new servers into splunk?

VijaySrrie
Builder

Hi All,

We have a python code to ingest MongoDB logs into splunk and we are successfully ingesting logs from old servers.

Now there is a requirement to ingest mongodb logs into splunk from new servers.

mongodb://USER:PASS@SERVER1:27017,SERVER2:27017/abc_analytics?replicaSet=mongo-replica</description>

This is how logs are ingested, now when I try the same for new servers, I get "Invalid Key error"

NOTE:

1) Firewall connectivity is working fine
2) MongoDB team says the password is correct

The password that is used, is that given by splunk team or the mongodb team?

If it is MongoDB team, where they need to check the password and the user id?

internal logs:

02-17-2022 18:45:50.916 +1100 WARN Application - Invalid key in stanza [abc_analytics://XXX-XXX-XXX] in /opt/splunk/etc/deployment-apps/modinput_abc_analytics_mongodb-XXX-XXX-XXX/local/inputs.conf, line 34: mongodb_uri (value: mongodb://Mongodbservername1.local:27017,Mongodbservername2.local:27017/abc_analytics?replicaSet=mongo-replica).\n
Labels (3)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...

Customer success is front and center at .conf25

Hi Splunkers, If you are not able to be at .conf25 in person, you can still learn about all the latest news ...