Deployment Architecture

Bulk loading DB_inputs for DBConnect - with rising column mode

kozanic_FF
Path Finder

Just wondering if there is anyone out there that has successfully managed to add in multiple new inputs to DBconnect when using Rising Column mode??

I have been attempting to do this today without much success.

Editing the db_inputs.conf file is OK, and the new inputs will show up in DBConnect, but even if I add in a corresponding file to hold the rising column value (even tried copying and editing an existing one), DBConnect complains saying "Error(s) occur when reading checkpoint"

I have multiple instances that I need to update, each with up to 30 inputs that need to be configured - I'm hoping there is a way that I can do this without having to edit each input to update the rising column value.

Appreciate any tips / advise people can offer.

Tags (2)
0 Karma

ianhar
New Member

I'm seeing this error too. My new inputs are not getting data after they're configured.

0 Karma

kozanic_FF
Path Finder

Hi @ianhar ,

Are you using WIndows box?

If so - check the permissions on the below folder:
?\Splunk\var\lib\splunk\modinputs\server\splunk_app_db_connect.

I have noticed that for some reason in windows environment - when you first go to this folder, it will say you don't have access and prompt you to gain access. For some reason - doing this updates the permissions for Splunk user and prevents it from being able to write to that directory.

I was having issues whereby SplunkDB was not able to update the files and kept ingesting duplicate data.

I have not re-tested doing the bulk updating of the checkpoint files since making this discovery - but it's possible it could be a related issue.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...