All Apps and Add-ons

Splunk DB Connect 2 and Splunk Add-on for Oracle Database: Why are my inputs getting forced disabled?

krwinters11
Path Finder

I am using Splunk DB Connect 2.0.6 and the Splunk Add-on for Oracle Database 3.3.0 with Splunk 6.3.0.

I have configured my inputs.conf in the local directory of the Splunk DB Connect 2 app. I configured this using the Oracle Add-on template for dbx2.

My problem is that the inputs will not stayed enabled. I enable them, but they seem to turn back to disabled fairly quickly and I am not getting events for many of the input types.

I am trying to monitor the performance on 11 oracle instances.

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

one of two things is probably happening -- there's a bunch of errors from the database, causing DBX to automatically disable instead of potentially gathering messed up data. If that's it, try to turn off auto-disabling
http://docs.splunk.com/Documentation/DBX/2.3.0/DeployDBX/inputsspec

Alternatively, you could have some sort of gremlin or config management tool overriding your configs.

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

Sounds like something is overwriting your configs? Are you using Deployment Server or a cluster deployer or something?

0 Karma

kaiserdba
New Member

I am downvoting this because it just contains followup questions and no suggestions for resolution. i have the same problem as the op...

0 Karma

ppablo
Retired

@kaiserdba

Please do not downvote users in this forum who are just trying to offer help by asking for more information/details from the op to help them troubleshoot. This is not how etiquette works in this community. Downvoting should only be used for posts that are suggesting a solution that is not supported and/or could be disastrous for someone's deployment.

Please check this previous Answers post on how you should be voting posts moving forward:
https://answers.splunk.com/answers/244111/proper-etiquette-and-timing-for-voting-here-on-ans.html

0 Karma

kaiserdba
New Member

Okay, but when the original post is included in the results of a search, it appears that there is an answer to this problem. It is QUITE frustrating to be led down a dead-end when one is trying to find a solution.

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...