All Apps and Add-ons

Splunk DB Connect 2.2.0 - The Configuration works but I can't find data in my "Search & Reporting" window

yzimmer
New Member

Hi!

I use Splunk Enterprise 6.3.3 (I also tried before with the Splunk Enterprise 6.4) with the app Splunk DB Connect 2.2.0 (I also tried with Splunk DB Connect 2.1.3)

It's always the same problem... I can configure easily Splunk DB Connect but I can't find the data ine the "Search & Reporting" window...
I don't know why because I can see the data in Operations/DB Inputs/MyInput/Choose and Preview Table......
alt text

In MyInput they say that i'm in "valid connection"...

At the step 4/4 they say "succesfully"

All work but I can searche in "Search & Reporting"

Can you help me please? I don't understand...

Thanx a lot

0 Karma

ryanoconnor
Builder

Do you have a Splunk enterprise license?

What schedule is your DB input set to run at?

0 Karma

yzimmer
New Member

Hi Ryanoconnor!

I have got Splunk Enterprise, I got it for free and I paid nothing : So I have got the "Enterprise Trial License" :
alt text
link text
http://www.hostingpics.net/viewer.php?id=367085licensing.png

Thanx for your answer!

0 Karma

JoanHorikawa
New Member

Hi ryanoconnor, Hi yzimmer,

I have the same problem except I'm using the Enterprise test/dev license. Does the DBConnect not work with this license as well?

Thanks in advance.

0 Karma

ryanoconnor
Builder

Unfortunately according to the documentation for DB Connect:

"Splunk DB Connect has not been tested and is not supported with Splunk Cloud, Splunk Free, or Splunk Light."

http://docs.splunk.com/Documentation/DBX/2.2.0/DeployDBX/Prerequisites#Splunk_Enterprise

0 Karma

yzimmer
New Member

Do you mean that Enterprise trial license is the same as Splunk Cloud, Splunk Free, or Splunk Light?

Thanx

0 Karma

ryanoconnor
Builder

Correct, an enterprise Trial license is Splunk Free

http://www.splunk.com/en_us/products/splunk-enterprise/free-vs-enterprise.html

0 Karma

TStrauch
Communicator

Hi, would be nice to know what your SPL-Command looks like.

Have you created an extra index and/or sourcetype for the DBConnect Data? Make sure you are searching against this specific index. (index= .... ).
If your index is not searched by default for the admin role you will get no results by simply doing [sourcetype=xxxx] or stuff like this.

0 Karma

yzimmer
New Member

Hi TStrauch!

My Splunk Command to search is just "*".

In DB Input/MyInput/Metadata I just write :
Source : dbx2.log
Sourcetype : dbx2
Index : main
Select Reource Pool : local

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...