All Apps and Add-ons

Splunk DB Connect: Data not indexing

behudelson
Path Finder

Hello, I have a test server and I am trying to use DBConnect to index some SQL data.

Everything appears to be configured appropriately.
In the input configuration screen, my search returns results. I've attached an image of the edit input screen.

I am running DB Connect version 3.1.4 on Splunk Enterprise 7.0.3 with a dev/test license.
Thank you for any help you can provide!

alt text

1 Solution

dhirendra761
Contributor

Hi @behudelson ,

I got this issue and it's related to HEC (HTTP Event Collector) Error, DB Connect injects data in Splunk using HEC. Unfortunately, this problem will occur only with MS server and DB Connect v 3.1.3.

To resolve this issue, you need to uninstall DBConnect v3.1.3 and Install DBConnect v3.1.2.

Thanks.
Dhirendra

View solution in original post

stanjkmiec
Engager

Can anyone advise if this issue still exists in DBX 3.31? I am experiencing what appears to be this issue and am curious if it has been resolved with newer releases. Thanks in advance. 

yassy
Explorer

Hello Can you send me the DB Connect Vs 3.1.2 please. That version is not available at splunkbase.

My email is : nicolasm@targetminds.com.ar

TKS for all

dhirendra761
Contributor

hi @yassy, app shared

0 Karma

dhirendra761
Contributor

@thaynaminuzzo ,
Please share your email id.

0 Karma

thaynaminuzzo
Explorer

@dhirendra761 my email is:
Thanks for responding

0 Karma

dhirendra761
Contributor

Shared....

0 Karma

thaynaminuzzo
Explorer

Thanks, it worked!

0 Karma

dhirendra761
Contributor

Hi @behudelson ,

I got this issue and it's related to HEC (HTTP Event Collector) Error, DB Connect injects data in Splunk using HEC. Unfortunately, this problem will occur only with MS server and DB Connect v 3.1.3.

To resolve this issue, you need to uninstall DBConnect v3.1.3 and Install DBConnect v3.1.2.

Thanks.
Dhirendra

L1_marrera
Explorer

Hello @dhirendra761,

Can I get it too?? I'm getting a "action=unable_to_write_batch java.io.IOException: HTTP Error 403: Forbidden" error.
email: ...

0 Karma

dhirendra761
Contributor

Your email Id please...

0 Karma

yassy
Explorer

Hello Can you send me the DB Connect Vs 3.1.2 please. That version is not available at splunkbase.
My email is : nicolasm@targetminds.com.ar
TKS for all

0 Karma

dhirendra761
Contributor

@yassy shared...Sorry, I missed you message 🙂

0 Karma

dhirendra761
Contributor

shared in your mail...

L1_marrera
Explorer

Got it, thanks!

0 Karma

alemarzuTM
Explorer

@dhirendra761

Hello there, Im having the same issue, could you send me DB Connect v.3.1.2 please? That version is not available at splunkbase.

email id: ...

Best regards,
AM.

0 Karma

dhirendra761
Contributor

@alemarzuTM ... shared..!!

0 Karma

alemarzuTM
Explorer

@dhirendra761 Thank you so much!

0 Karma

maciep
Champion

dumb question, did you create the index?

you can always search the _internal index for your input name to see if there are any errors (I believe dbconnect has a health dashboard where you may be able to see similar log data)

behudelson
Path Finder

Not a dumb question, but yes, I created the index 🙂

Also, I did search _internal and the log entries aren't very useful. This 'status=FAILED' doesn't give me much information. (I obfuscated sensitive details with ++++)

2019-01-10 10:16:00.202 -0500 INFO c.s.dbx.server.task.listeners.JobMetricsListener - action=collect_job_metrics connection=+++++++ jdbc_url=jdbc:jtds:sqlserver://++++++++++:14330/IntegrationMart;useCursors=true;domain=+++++++;useNTLMv2=false db_read_time=2 hec_record_process_time=23 format_hec_success_count=57 status=FAILED input_name=++++++++++_fact batch_size=1000 error_threshold=N/A is_jmx_monitoring=false start_time=2019-01-10_10:16:00 end_time=2019-01-10_10:16:00 duration=190 read_count=57 write_count=0 filtered_count=0 error_count=0

0 Karma

dhirendra761
Contributor

hi @behudelson Which Operating Sysytem (OS) you are using... Is it Microsoft Server ??

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...