Splunk Enterprise

DB Connect Log Files

dorgra
Path Finder

We're using DB Connect v3.1.4
Occasionally, an SQL Query in a Data Lab Input gets changed. I need to know where the log files are located and if they are ingested into Splunk. That way, I can alert when the query is altered. 

Labels (2)
0 Karma
1 Solution

dorgra
Path Finder

Figured this one out by gleaning information from the Deploy DBX documentation at 

https://docs.splunk.com/Documentation/DBX/3.5.0/DeployDBX/AboutSplunkDBConnect

In the DBConnect Configuration -> Settings, under Logging, the dbinput should be changed to DEBUG in order to have the app write the db_inputs.conf changes to log. 

index=_internal sourcetype=dbx* db_input action=build_scheduled_job_for_db_input

I do NOT know how verbose logging is with this setting. 

View solution in original post

0 Karma

dorgra
Path Finder

Figured this one out by gleaning information from the Deploy DBX documentation at 

https://docs.splunk.com/Documentation/DBX/3.5.0/DeployDBX/AboutSplunkDBConnect

In the DBConnect Configuration -> Settings, under Logging, the dbinput should be changed to DEBUG in order to have the app write the db_inputs.conf changes to log. 

index=_internal sourcetype=dbx* db_input action=build_scheduled_job_for_db_input

I do NOT know how verbose logging is with this setting. 

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...