Splunk Enterprise

Splunk connect db not running queries after adding input

markawad
Engager

Hello,

I am on splunk 7.0.2, which is configured in a distributed environment. I installed splunk connect db on a SHC. Then from one of my search heads in the UI, I added my first input. (Note the connection to the db is fine, executing the sql query during setup, yields the expected result.)

However, after adding the input, I can see that connect db does not run the query at all, it ignores the frequency at which the query would run. This is seen in $splunk_home/var/log/splunk/splunk_app_db_connect_server.log

The data is not saved at all, I am not sure what am I missing or doing wrong. 

What is quite strange is that I cannot find any errors in the log that would help me at least debug why this is being caused, besides this error:  ch.qos.logback.core.Appender.error in splunk_app_db_connect_health_metrics.log

Note: The SHC is configured properly and is connected with the indexers. 

I have been facing a lot of issues with this.  Please help me find the solution or hint me towards how I can debug this.

Thanks,
Mark

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The problem began by configuring a DB Connect input on a SHC.  Inputs must be installed on a heavy forwarder.  See https://docs.splunk.com/Documentation/DBX/3.4.0/DeployDBX/Distributeddeployment

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

The problem began by configuring a DB Connect input on a SHC.  Inputs must be installed on a heavy forwarder.  See https://docs.splunk.com/Documentation/DBX/3.4.0/DeployDBX/Distributeddeployment

---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...