All Apps and Add-ons

Troubleshooting DBConnect- Why did data stop indexing?

phamxuantung
Communicator

Hello,

I'm troubleshooting a possible problems with the dbconnect app. We setup a dbinput that indexing with 90 second frequency, raising column by time. We have to index these data fairly frequently for monitoring.

At around 4PM, monitoring team told me that data has stop indexing, I check indexing log and found no bug

Capture.PNG

The log said input_mode=tail events=0, and repeat in 30 minutes until we have normal index log with rising column check point again.

I checked with SQL and the we do have data in between those time.So I want to pinpoint the root problems so we don't encounter this again.

Is this the problems with networking, oracleBD, or is this from splunk (I highly doubt it because I don't do anything and it continue indexing 30 min after)

Labels (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

if I understood right this start to work again and indexed all "missing" data without any intervention on splunk side? If so then it's quite obviously that the issue was somewhere else like network, DB or something else.

Could there be e.g. some maintenance jobs on DB side which set exclusive lock for those rows?

r. Ismo

0 Karma

phamxuantung
Communicator

But the thing is, we can index data from another db on the same server ip just fine, only that schema and view have that problem. And I just confirm with the DB team and there's no problem on their side.

Do Splunk have log somewhere that can indicate or pinpoint what the problem is?

It's for prevent it for the future, and I don't want to sound petty, but I don't want people pin this problems on splunk and me.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

When you have installed DBX on SH side you can use it’s monitoring views to get information about how it works. It also write it’s own log files under …/logs/splunk.

 

0 Karma
Get Updates on the Splunk Community!

.conf25 Registration is OPEN!

Ready. Set. Splunk! Your favorite Splunk user event is back and better than ever. Get ready for more technical ...

Detecting Cross-Channel Fraud with Splunk

This article is the final installment in our three-part series exploring fraud detection techniques using ...

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...