Splunk Search

Splunk DB Connect 1.1.6: Why are MS SQL dbquery results sent to an index using a database input not parsing all fields correctly?

aervillar
New Member

I am using Splunk DB Connect 1.1.6 to connect to a SQL database. The dbquery using select * from databasename works fine and I can see all fields with the correct values.

My next step is to create a data input using a database input. Everything looks to work fine, but I realize the parsing is not correct. Splunk is not bringing in all the fields.... I am now sending the data to a lookup table, and then from that table, indexing, but I am curious why and how I can fix this issue.

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

I don't understand why you would do that instead of using a regular database input? dbquery into a collect introduces a bunch of needless complexity around timestamp detection that could be root of your problem.

0 Karma

avillarworldban
New Member

Maybe I was not clear, I am using dbconnect but the parsing on SQL dbs does not work as expected when sending the data to a index. I need historical data so I have to send somewhere. Indexing does not work so I have to send to a lookup first and then from the lookup to the index it works fine. Connection to oracle are OK and I can collect data daily with dbconnect and send directly to the index. Maybe dbconnect 2 fixed this issue.

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

DB Connect 2 is easier to use, but it's impossible to tell what your issue is without looking at data and SQL statements. You're probably better off opening a support case than posting on a forum.

0 Karma

avillarworldban
New Member

I don't know other way to connect to a database. This was recommended by a Splunk engineer to download the apps and the use it to connect. Any link to your suggestion would help me. Thanks

0 Karma

ppablo
Retired

Hi @aervillar

Are you using DB Connect 1 or DB Connect 2?

0 Karma

aervillar
New Member

I gues version 1.1.6 (from about link)

0 Karma

ppablo
Retired

Thanks for getting back. I was editing your post to improve visibility of your issue, but needed to know the correct version to tag the official app appropriately.

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...