Hello,
we have 4 search heads on our installation of Splunk 6.5.1, with DBConnect 2.4.0.
Suddenly, all the search heads started feeding data into Splunk via DBConnect, while, some days ago, only one of the search heads per time was executing the scheduled query and writing on the database.
What can we check to avoid this behavior (that puts 4x data on the index)?
Thanks
DBconnect < 3.x allows for scheduled inputs via search head cluster.
Maybe an issue with who is the captain?
Is dbconnect the only issue?
Hello,
as far as we could investigate, only dbconnect is giving problems (fetching 4x times the data, instead of doing only one fetch from the database). Note, as I said, that this problem started two days ago after this system has been working for years without problems. Noone seems to have touched the configuration, though.
Thanks
How are you ingesting data from Splunk, using data inputs? AFAIK, SHC doesn't support DB Connect inputs.
Are you SH clustered?
Yes, I think they are.