All Apps and Add-ons

Why has the Splunk DB Connect 3.1.1 stopped sending data to indexers?

heybails88
Path Finder

I have 4 data inputs built off of a MySQL connection. Two of them work, while the other two don't. I've tried changing the "Max Rows to Retrieve", the "Fetch Size", the "Execution Frequency", the JDBC URL to adjust for the timezone, rebuilding the indexer to another name, disabling and re-enabling, and tried to change things from a batch to a rising input type. Nothing is working. I know the data is there and current, because I can use other tools to extract it. I don't think it's the indexer. This has something to do with how DBX is grabbing the data, but I have no idea what could have changed to just stop the data from coming in. Any help would be appreciated.

0 Karma
1 Solution

heybails88
Path Finder

I changed the query history to only go back a year and that seemed to open things up.

View solution in original post

0 Karma

heybails88
Path Finder

I changed the query history to only go back a year and that seemed to open things up.

0 Karma

heybails88
Path Finder

Just to add, when I run the same query in another tool, the data is there and current. This has to be in the DB connect config somewhere. The weird thing is that it was working, and now it's not. I noticed I cannot set up a Rising input no matter what I do. So maybe the issue is there.

0 Karma

harsmarvania57
SplunkTrust
SplunkTrust

Any error in DB connect log files ?

0 Karma

heybails88
Path Finder

no, nothing. I have a ticket opened with support, but was hoping to see if anyone else had this experience with 3.1.1?

0 Karma

heybails88
Path Finder

I changed the query history to only go back a year and that seemed to open things up.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...