Getting Data In

Unable to configure Sybase audit logs with DB Connect 3 on Splunk 6.6

gadepoonam
Explorer

I am trying to configure Sybase sysaudits_01 table with DB connect in SPlunk. sysaudits_01 table has eventtime column which is having datetime data type. I am trying to configure datetime as rising column for Splunk DB connect: Data input.
On query editior with check point value, query executes fine. But when i try to save the configuration, it does not save the config.
It give following error in db connect splunk server log file.
Can you please suggest?

2017-07-10 09:00:33.547 +0000 [QuartzScheduler_Worker-25] INFO c.s.d.s.dbinput.recordreader.DbInputRecordReader - action=db_input_record_reader_is_opened input_task="sybase_audit" query=SELECT * FROM "sybsecurity"."dbo"."sysaudits_01" where CONVERT(CHAR(19), eventtime, 23) > CONVERT(CHAR(19), ?, 23) order by CONVERT(CHAR(19), eventtime, 23)
2017-07-10 09:00:33.551 +0000 [QuartzScheduler_Worker-25] INFO c.s.d.server.dbinput.task.DbInputCheckpointManager - action=loading_checkpoint value=null
2017-07-10 09:00:33.552 +0000 [QuartzScheduler_Worker-25] ERROR org.easybatch.core.job.BatchJob - Unable to open record reader
java.lang.NullPointerException: null
at com.fasterxml.jackson.core.JsonFactory.createParser(JsonFactory.java:879)
at com.fasterxml.jackson.databind.ObjectMapper.readValue(ObjectMapper.java:2833)
at com.splunk.dbx.server.dbinput.task.DbInputCheckpointManager.parseOutput(DbInputCheckpointManager.java:184)
at com.splunk.dbx.server.dbinput.task.DbInputCheckpointManager.loadImpl(DbInputCheckpointManager.java:247)
at com.splunk.dbx.server.dbinput.task.DbInputCheckpointManager.load(DbInputCheckpointManager.java:132)
at com.splunk.dbx.server.dbinput.task.DbInputTask.loadCheckpoint(DbInputTask.java:88)
at com.splunk.dbx.server.dbinput.recordreader.DbInputRecordReader.open(DbInputRecordReader.java:57)
at org.easybatch.core.job.BatchJob.openReader(BatchJob.java:117)
at org.easybatch.core.job.BatchJob.call(BatchJob.java:74)
at org.easybatch.extensions.quartz.Job.execute(Job.java:59)
at org.quartz.core.JobRunShell.run(JobRunShell.java:202)
at org.quartz.simpl.SimpleThreadPool$WorkerThread.run(SimpleThreadPool.java:573)
2017-07-10 09:00:33.552 +0000 [QuartzScheduler_Worker-25] INFO org.easybatch.core.job.BatchJob - Job 'sybase_audit' finished with status: FAILED
2017-07-10 09:01:33.548 +0000 [QuartzScheduler_Worker-26] INFO org.easybatch.core.job.BatchJob - Job 'sybase_audit' starting
2017-07-10 09:01:33.549 +0000 [QuartzScheduler_Worker-26] INFO org.easybatch.core.job.BatchJob - Batch size: 1,000
2017-07-10 09:01:33.549 +0000 [QuartzScheduler_Worker-26] INFO org.easybatch.core.job.BatchJob - Error threshold: N/A
2017-07-10 09:01:33.549 +0000 [QuartzScheduler_Worker-26] INFO org.easybatch.core.job.BatchJob - Jmx monitoring: false
2017-07-10 09:01:33.549 +0000 [QuartzScheduler_Worker-26] INFO c.s.d.s.dbinput.recordreader.DbInputRecordReader - action=db_input_record_reader_is_opened input_task="sybase_audit" query=SELECT * FROM "sybsecurity"."dbo"."sysaudits_01" where CONVERT(CHAR(19), eventtime, 23) > CONVERT(CHAR(19), ?, 23) order by CONVERT(CHAR(19), eventtime, 23)
2017-07-10 09:01:33.556 +0000 [QuartzScheduler_Worker-26] INFO c.s.d.server.dbinput.task.DbInputCheckpointManager - action=loading_checkpoint value=null
2017-07-10 09:01:33.557 +0000 [QuartzScheduler_Worker-26] ERROR org.easybatch.core.job.BatchJob - Unable to open record reader
java.lang.NullPointerException: null
at com.fasterxml.jackson.core.JsonFactory.createParser(JsonFactory.java:879)
at com.fasterxml.jackson.databind.ObjectMapper.readValue(ObjectMapper.java:2833)
at com.splunk.dbx.server.dbinput.task.DbInputCheckpointManager.parseOutput(DbInputCheckpointManager.java:184)
at com.splunk.dbx.server.dbinput.task.DbInputCheckpointManager.loadImpl(DbInputCheckpointManager.java:247)
at com.splunk.dbx.server.dbinput.task.DbInputCheckpointManager.load(DbInputCheckpointManager.java:132)
at com.splunk.dbx.server.dbinput.task.DbInputTask.loadCheckpoint(DbInputTask.java:88)
at com.splunk.dbx.server.dbinput.recordreader.DbInputRecordReader.open(DbInputRecordReader.java:57)
at org.easybatch.core.job.BatchJob.openReader(BatchJob.java:117)
at org.easybatch.core.job.BatchJob.call(BatchJob.java:74)
at org.easybatch.extensions.quartz.Job.execute(Job.java:59)
at org.quartz.core.JobRunShell.run(JobRunShell.java:202)
at org.quartz.simpl.SimpleThreadPool$WorkerThread.run(SimpleThreadPool.java:573)

Tags (1)
0 Karma
1 Solution

gadepoonam
Explorer

Fixed the error bu configuring DB input with following query for rising column

Select * from (
SELECT *, (cast(
cast(datepart(year, eventtime) as varchar) +
right('0' + cast (datepart(month, eventtime) as varchar),2) +
right('0' + cast (datepart(day,eventtime) as varchar),2) +

right('0' + cast (datepart(hour,eventtime) as varchar),2) +
right('0' + cast (datepart(minute,eventtime) as varchar),2) +
right('0' + cast (datepart(second,eventtime) as varchar),2) +
right('0' + cast (datepart(millisecond,eventtime) as varchar),3)
as numeric(18,0))) as id
FROM "sybsecurity"."dbo"."sysaudits_01" ) dt
where dt.id > ?
order by dt.id

View solution in original post

0 Karma

gadepoonam
Explorer

Fixed the error bu configuring DB input with following query for rising column

Select * from (
SELECT *, (cast(
cast(datepart(year, eventtime) as varchar) +
right('0' + cast (datepart(month, eventtime) as varchar),2) +
right('0' + cast (datepart(day,eventtime) as varchar),2) +

right('0' + cast (datepart(hour,eventtime) as varchar),2) +
right('0' + cast (datepart(minute,eventtime) as varchar),2) +
right('0' + cast (datepart(second,eventtime) as varchar),2) +
right('0' + cast (datepart(millisecond,eventtime) as varchar),3)
as numeric(18,0))) as id
FROM "sybsecurity"."dbo"."sysaudits_01" ) dt
where dt.id > ?
order by dt.id

0 Karma

gadepoonam
Explorer

Fixed the error bu configuring DB input with following query for rising column

Select * from (
SELECT *, (cast(
cast(datepart(year, eventtime) as varchar) +
right('0' + cast (datepart(month, eventtime) as varchar),2) +
right('0' + cast (datepart(day,eventtime) as varchar),2) +

right('0' + cast (datepart(hour,eventtime) as varchar),2) +
right('0' + cast (datepart(minute,eventtime) as varchar),2) +
right('0' + cast (datepart(second,eventtime) as varchar),2) +
right('0' + cast (datepart(millisecond,eventtime) as varchar),3)
as numeric(18,0))) as id
FROM "sybsecurity"."dbo"."sysaudits_01" ) dt
where dt.id > ?
order by dt.id

0 Karma

gadepoonam
Explorer

Did anyone get a chance to look into it please?

0 Karma
Get Updates on the Splunk Community!

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability As businesses scale ...