We are trying to ingest the data from our MySQL server, but we got this error.
Mysql version: 5.6.31
CentOS: 7
Sounds like you should disable query wrapping:
* http://docs.splunk.com/Documentation/DBX/2.3.0/DeployDBX/SQLtipsandtricks#Use_inline_views_.28query_...
* http://docs.splunk.com/Documentation/DBX/2.3.0/DeployDBX/Createandmanagedatabaseinputs
* http://docs.splunk.com/Documentation/DBX/2.3.0/DeployDBX/Troubleshooting#Database_inputs_or_lookups_...
* http://docs.splunk.com/Documentation/DBX/2.3.0/DeployDBX/Commands#dbxquery
Brilliant! Disabling query wrapping fixed my issue. I read that section prior but didn't understand how it related to the issue. Thanks for the info.
We have the same problem. The DB side is caused because the database server is running out of disk space. For us it is /tmp but based on your error it looks like /home/tmp/. The problem we have is the temp file is growing bigger than the free space and then it errors out, the temp file is removed, and we get no data in Splunk. I have not been able to figure out why creating the temp file is using up all of the free space (26GB for a less then 2 GB database).