Splunk Enterprise

DB Connect Log Files

dorgra
Path Finder

We're using DB Connect v3.1.4
Occasionally, an SQL Query in a Data Lab Input gets changed. I need to know where the log files are located and if they are ingested into Splunk. That way, I can alert when the query is altered. 

Labels (2)
0 Karma
1 Solution

dorgra
Path Finder

Figured this one out by gleaning information from the Deploy DBX documentation at 

https://docs.splunk.com/Documentation/DBX/3.5.0/DeployDBX/AboutSplunkDBConnect

In the DBConnect Configuration -> Settings, under Logging, the dbinput should be changed to DEBUG in order to have the app write the db_inputs.conf changes to log. 

index=_internal sourcetype=dbx* db_input action=build_scheduled_job_for_db_input

I do NOT know how verbose logging is with this setting. 

View solution in original post

0 Karma

dorgra
Path Finder

Figured this one out by gleaning information from the Deploy DBX documentation at 

https://docs.splunk.com/Documentation/DBX/3.5.0/DeployDBX/AboutSplunkDBConnect

In the DBConnect Configuration -> Settings, under Logging, the dbinput should be changed to DEBUG in order to have the app write the db_inputs.conf changes to log. 

index=_internal sourcetype=dbx* db_input action=build_scheduled_job_for_db_input

I do NOT know how verbose logging is with this setting. 

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...