All Apps and Add-ons

What is causing Splunk Db connect indexing issue?

Ritu
Explorer

In Splunk db connect some specific data labs are not indexing properly to Splunk means not forwarding its data to Splunk  search head from the databases where as those databases are executing fine what could be the issue is it on server or on Splunk?

Labels (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

can you open more what you have tried and what has happened?

r. Ismo

0 Karma

Ritu
Explorer

There are certain datalabs which are created on a specific server when we run/execute those SQL queries its executing with proper data but the moment we are checking the indexing of that server like, index=dbconnect there are 0 events on the server.
Can it be a server issue somehow?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Have you defined any data inputs or just those dbxqueries?

You need separate data inputs on HF to get data into indexes with DBX on distributed environment. Over that you could also have DBX configured on SH side to do those dbxqueries and monitoring how db inputs are working.

0 Karma

Ritu
Explorer

Yes, those are done still facing issue where as to add in there are distributed environment where different Servers are hosted to different cloud platform and each cloud platform has a DB app configured on it .
So, other cloud platforms we are not facing the issues we are specifically facing issues here.
Could it be the DB servers versions not matching the Splunk DB version ?
Current Splunk DB version is 3.4.2

0 Karma

isoutamo
SplunkTrust
SplunkTrust

If you could do db query on that HF or what ever node your data collection is then also db inputs should work. When you are defining db input you need to create SQL query and if it works then it should also index that data after you have save and enabled it.

You should check that outputs.conf is correct and it send your data to correct environment if/when you have several in use.

0 Karma

Ritu
Explorer

I agree on the point  but seems its not working post saving the SQL queries and executing them.
Could it be the DB servers versions not matching the Splunk DB version ?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Basically everything is possible.

Have you found anything from _internal logs about dbx actions and/or dbx dashboards which could lead you to correct direction?

0 Karma
Get Updates on the Splunk Community!

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...