Getting Data In

how to list metadata from dbconnect inputs?

3DGjos
Communicator

Hello,

I have to survey our client's dbx inputs, with their metadata (index, sourcetype) but the command:

| rest splunk_server=local /servicesNS/nobody/splunk_app_db_connect/configs/inputs

is not giving me the inputs at all. Can you please help me to make the query? I need the input name, with the respective connection and metadata, for all inputs.

Thanks!

Tags (4)
0 Karma

ArchieCrozier
Path Finder

@hiteshdholakiya , That is exactly what I needed.  Karma added.  Wish this was marked a the solution.  Worked perfect for what I needed.  THANK YOU!!

0 Karma

hiteshdholakiya
Explorer

Hello @3DGjos 

Try the following:

For listing out all inputs on dbconnect v3:

 

| rest splunk_server=local /servicesNS/nobody/splunk_app_db_connect/configs/conf-db_inputs/

 

 

For listing out all connections on dbconnect v3:

 

| rest splunk_server=local /servicesNS/nobody/splunk_app_db_connect/configs/conf-db_connections/

 

 

For listing out all identities on dbconnect v3:

 

| rest splunk_server=local /servicesNS/nobody/splunk_app_db_connect/configs/conf-identities/

 

 

isoutamo
SplunkTrust
SplunkTrust

When DBX is installed also on SH layer there are monitoring part which is showing  status information of whole environment (including inputs on HFs when all nodes sent internal logs to the IDX layer).

0 Karma

arrangineni
Path Finder

3DGjos

By any chance you got the REST command working for DB Connect inputs.. I am trying to find similar information but nothing working at this point.

0 Karma

hiteshdholakiya
Explorer

Hello @arrangineni 

Try the following:

For listing out all inputs on dbconnect v3:

| rest splunk_server=local /servicesNS/nobody/splunk_app_db_connect/configs/conf-db_inputs/

 

For listing out all connections on dbconnect v3:

| rest splunk_server=local /servicesNS/nobody/splunk_app_db_connect/configs/conf-db_connections/

 

For listing out all identities on dbconnect v3:

| rest splunk_server=local /servicesNS/nobody/splunk_app_db_connect/configs/conf-identities/

 

Tags (1)
0 Karma

arrangineni
Path Finder

@hiteshdholakiya . Thanks this is exactly what I am looking for.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...