All Apps and Add-ons

Why has the Splunk DB Connect 3.1.1 stopped sending data to indexers?

heybails88
Path Finder

I have 4 data inputs built off of a MySQL connection. Two of them work, while the other two don't. I've tried changing the "Max Rows to Retrieve", the "Fetch Size", the "Execution Frequency", the JDBC URL to adjust for the timezone, rebuilding the indexer to another name, disabling and re-enabling, and tried to change things from a batch to a rising input type. Nothing is working. I know the data is there and current, because I can use other tools to extract it. I don't think it's the indexer. This has something to do with how DBX is grabbing the data, but I have no idea what could have changed to just stop the data from coming in. Any help would be appreciated.

0 Karma
1 Solution

heybails88
Path Finder

I changed the query history to only go back a year and that seemed to open things up.

View solution in original post

0 Karma

heybails88
Path Finder

I changed the query history to only go back a year and that seemed to open things up.

0 Karma

heybails88
Path Finder

Just to add, when I run the same query in another tool, the data is there and current. This has to be in the DB connect config somewhere. The weird thing is that it was working, and now it's not. I noticed I cannot set up a Rising input no matter what I do. So maybe the issue is there.

0 Karma

harsmarvania57
Ultra Champion

Any error in DB connect log files ?

0 Karma

heybails88
Path Finder

no, nothing. I have a ticket opened with support, but was hoping to see if anyone else had this experience with 3.1.1?

0 Karma

heybails88
Path Finder

I changed the query history to only go back a year and that seemed to open things up.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...