Splunk Enterprise

DB Connect Log Files

dorgra
Path Finder

We're using DB Connect v3.1.4
Occasionally, an SQL Query in a Data Lab Input gets changed. I need to know where the log files are located and if they are ingested into Splunk. That way, I can alert when the query is altered. 

Labels (2)
0 Karma
1 Solution

dorgra
Path Finder

Figured this one out by gleaning information from the Deploy DBX documentation at 

https://docs.splunk.com/Documentation/DBX/3.5.0/DeployDBX/AboutSplunkDBConnect

In the DBConnect Configuration -> Settings, under Logging, the dbinput should be changed to DEBUG in order to have the app write the db_inputs.conf changes to log. 

index=_internal sourcetype=dbx* db_input action=build_scheduled_job_for_db_input

I do NOT know how verbose logging is with this setting. 

View solution in original post

0 Karma

dorgra
Path Finder

Figured this one out by gleaning information from the Deploy DBX documentation at 

https://docs.splunk.com/Documentation/DBX/3.5.0/DeployDBX/AboutSplunkDBConnect

In the DBConnect Configuration -> Settings, under Logging, the dbinput should be changed to DEBUG in order to have the app write the db_inputs.conf changes to log. 

index=_internal sourcetype=dbx* db_input action=build_scheduled_job_for_db_input

I do NOT know how verbose logging is with this setting. 

0 Karma
Get Updates on the Splunk Community!

See Splunk Platform & Observability Innovations at Cisco Live EMEA

Hi Splunkers, Learn about what’s next for Splunk Platform at Cisco Live EMEA.  Data silos are a big challenge ...

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...