Getting Data In

Unable to configure Sybase audit logs with DB Connect 3 on Splunk 6.6

gadepoonam
Explorer

I am trying to configure Sybase sysaudits_01 table with DB connect in SPlunk. sysaudits_01 table has eventtime column which is having datetime data type. I am trying to configure datetime as rising column for Splunk DB connect: Data input.
On query editior with check point value, query executes fine. But when i try to save the configuration, it does not save the config.
It give following error in db connect splunk server log file.
Can you please suggest?

2017-07-10 09:00:33.547 +0000 [QuartzScheduler_Worker-25] INFO c.s.d.s.dbinput.recordreader.DbInputRecordReader - action=db_input_record_reader_is_opened input_task="sybase_audit" query=SELECT * FROM "sybsecurity"."dbo"."sysaudits_01" where CONVERT(CHAR(19), eventtime, 23) > CONVERT(CHAR(19), ?, 23) order by CONVERT(CHAR(19), eventtime, 23)
2017-07-10 09:00:33.551 +0000 [QuartzScheduler_Worker-25] INFO c.s.d.server.dbinput.task.DbInputCheckpointManager - action=loading_checkpoint value=null
2017-07-10 09:00:33.552 +0000 [QuartzScheduler_Worker-25] ERROR org.easybatch.core.job.BatchJob - Unable to open record reader
java.lang.NullPointerException: null
at com.fasterxml.jackson.core.JsonFactory.createParser(JsonFactory.java:879)
at com.fasterxml.jackson.databind.ObjectMapper.readValue(ObjectMapper.java:2833)
at com.splunk.dbx.server.dbinput.task.DbInputCheckpointManager.parseOutput(DbInputCheckpointManager.java:184)
at com.splunk.dbx.server.dbinput.task.DbInputCheckpointManager.loadImpl(DbInputCheckpointManager.java:247)
at com.splunk.dbx.server.dbinput.task.DbInputCheckpointManager.load(DbInputCheckpointManager.java:132)
at com.splunk.dbx.server.dbinput.task.DbInputTask.loadCheckpoint(DbInputTask.java:88)
at com.splunk.dbx.server.dbinput.recordreader.DbInputRecordReader.open(DbInputRecordReader.java:57)
at org.easybatch.core.job.BatchJob.openReader(BatchJob.java:117)
at org.easybatch.core.job.BatchJob.call(BatchJob.java:74)
at org.easybatch.extensions.quartz.Job.execute(Job.java:59)
at org.quartz.core.JobRunShell.run(JobRunShell.java:202)
at org.quartz.simpl.SimpleThreadPool$WorkerThread.run(SimpleThreadPool.java:573)
2017-07-10 09:00:33.552 +0000 [QuartzScheduler_Worker-25] INFO org.easybatch.core.job.BatchJob - Job 'sybase_audit' finished with status: FAILED
2017-07-10 09:01:33.548 +0000 [QuartzScheduler_Worker-26] INFO org.easybatch.core.job.BatchJob - Job 'sybase_audit' starting
2017-07-10 09:01:33.549 +0000 [QuartzScheduler_Worker-26] INFO org.easybatch.core.job.BatchJob - Batch size: 1,000
2017-07-10 09:01:33.549 +0000 [QuartzScheduler_Worker-26] INFO org.easybatch.core.job.BatchJob - Error threshold: N/A
2017-07-10 09:01:33.549 +0000 [QuartzScheduler_Worker-26] INFO org.easybatch.core.job.BatchJob - Jmx monitoring: false
2017-07-10 09:01:33.549 +0000 [QuartzScheduler_Worker-26] INFO c.s.d.s.dbinput.recordreader.DbInputRecordReader - action=db_input_record_reader_is_opened input_task="sybase_audit" query=SELECT * FROM "sybsecurity"."dbo"."sysaudits_01" where CONVERT(CHAR(19), eventtime, 23) > CONVERT(CHAR(19), ?, 23) order by CONVERT(CHAR(19), eventtime, 23)
2017-07-10 09:01:33.556 +0000 [QuartzScheduler_Worker-26] INFO c.s.d.server.dbinput.task.DbInputCheckpointManager - action=loading_checkpoint value=null
2017-07-10 09:01:33.557 +0000 [QuartzScheduler_Worker-26] ERROR org.easybatch.core.job.BatchJob - Unable to open record reader
java.lang.NullPointerException: null
at com.fasterxml.jackson.core.JsonFactory.createParser(JsonFactory.java:879)
at com.fasterxml.jackson.databind.ObjectMapper.readValue(ObjectMapper.java:2833)
at com.splunk.dbx.server.dbinput.task.DbInputCheckpointManager.parseOutput(DbInputCheckpointManager.java:184)
at com.splunk.dbx.server.dbinput.task.DbInputCheckpointManager.loadImpl(DbInputCheckpointManager.java:247)
at com.splunk.dbx.server.dbinput.task.DbInputCheckpointManager.load(DbInputCheckpointManager.java:132)
at com.splunk.dbx.server.dbinput.task.DbInputTask.loadCheckpoint(DbInputTask.java:88)
at com.splunk.dbx.server.dbinput.recordreader.DbInputRecordReader.open(DbInputRecordReader.java:57)
at org.easybatch.core.job.BatchJob.openReader(BatchJob.java:117)
at org.easybatch.core.job.BatchJob.call(BatchJob.java:74)
at org.easybatch.extensions.quartz.Job.execute(Job.java:59)
at org.quartz.core.JobRunShell.run(JobRunShell.java:202)
at org.quartz.simpl.SimpleThreadPool$WorkerThread.run(SimpleThreadPool.java:573)

Tags (1)
0 Karma
1 Solution

gadepoonam
Explorer

Fixed the error bu configuring DB input with following query for rising column

Select * from (
SELECT *, (cast(
cast(datepart(year, eventtime) as varchar) +
right('0' + cast (datepart(month, eventtime) as varchar),2) +
right('0' + cast (datepart(day,eventtime) as varchar),2) +

right('0' + cast (datepart(hour,eventtime) as varchar),2) +
right('0' + cast (datepart(minute,eventtime) as varchar),2) +
right('0' + cast (datepart(second,eventtime) as varchar),2) +
right('0' + cast (datepart(millisecond,eventtime) as varchar),3)
as numeric(18,0))) as id
FROM "sybsecurity"."dbo"."sysaudits_01" ) dt
where dt.id > ?
order by dt.id

View solution in original post

0 Karma

gadepoonam
Explorer

Fixed the error bu configuring DB input with following query for rising column

Select * from (
SELECT *, (cast(
cast(datepart(year, eventtime) as varchar) +
right('0' + cast (datepart(month, eventtime) as varchar),2) +
right('0' + cast (datepart(day,eventtime) as varchar),2) +

right('0' + cast (datepart(hour,eventtime) as varchar),2) +
right('0' + cast (datepart(minute,eventtime) as varchar),2) +
right('0' + cast (datepart(second,eventtime) as varchar),2) +
right('0' + cast (datepart(millisecond,eventtime) as varchar),3)
as numeric(18,0))) as id
FROM "sybsecurity"."dbo"."sysaudits_01" ) dt
where dt.id > ?
order by dt.id

0 Karma

gadepoonam
Explorer

Fixed the error bu configuring DB input with following query for rising column

Select * from (
SELECT *, (cast(
cast(datepart(year, eventtime) as varchar) +
right('0' + cast (datepart(month, eventtime) as varchar),2) +
right('0' + cast (datepart(day,eventtime) as varchar),2) +

right('0' + cast (datepart(hour,eventtime) as varchar),2) +
right('0' + cast (datepart(minute,eventtime) as varchar),2) +
right('0' + cast (datepart(second,eventtime) as varchar),2) +
right('0' + cast (datepart(millisecond,eventtime) as varchar),3)
as numeric(18,0))) as id
FROM "sybsecurity"."dbo"."sysaudits_01" ) dt
where dt.id > ?
order by dt.id

0 Karma

gadepoonam
Explorer

Did anyone get a chance to look into it please?

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...