Just after installing the Splunk_TA_oracle, I noticed that my splunk instance stopped collecting logs :
- no more files monitored
- no summary indexing
And from a btool and the manager I saw that all "monitor" and "batch" were disabled.
Because of the setting in etc/apps/Splunk_TA_oracle/default/inputs.conf
[default]
disabled = 1
This setting applied to all the other inputs on the other apps. and cannot be removed from the UI
The workaround was
or enable the defaults adding in $SPLUNK_HOME/etc/apps/Splunk_TA_oracle/local/inputs.conf
[default]
disabled = 0
The workaround was
or enable the defaults adding in $SPLUNK_HOME/etc/apps/Splunk_TA_oracle/local/inputs.conf
[default]
disabled = 0
Version 3.1.2 solves this problem. We've also updated our best practices training.