Splunk Enterprise

DB Connect Log Files

dorgra
Path Finder

We're using DB Connect v3.1.4
Occasionally, an SQL Query in a Data Lab Input gets changed. I need to know where the log files are located and if they are ingested into Splunk. That way, I can alert when the query is altered. 

Labels (2)
0 Karma
1 Solution

dorgra
Path Finder

Figured this one out by gleaning information from the Deploy DBX documentation at 

https://docs.splunk.com/Documentation/DBX/3.5.0/DeployDBX/AboutSplunkDBConnect

In the DBConnect Configuration -> Settings, under Logging, the dbinput should be changed to DEBUG in order to have the app write the db_inputs.conf changes to log. 

index=_internal sourcetype=dbx* db_input action=build_scheduled_job_for_db_input

I do NOT know how verbose logging is with this setting. 

View solution in original post

0 Karma

dorgra
Path Finder

Figured this one out by gleaning information from the Deploy DBX documentation at 

https://docs.splunk.com/Documentation/DBX/3.5.0/DeployDBX/AboutSplunkDBConnect

In the DBConnect Configuration -> Settings, under Logging, the dbinput should be changed to DEBUG in order to have the app write the db_inputs.conf changes to log. 

index=_internal sourcetype=dbx* db_input action=build_scheduled_job_for_db_input

I do NOT know how verbose logging is with this setting. 

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...