Splunk® DB Connect

Release Notes

Download manual as PDF

This documentation does not apply to the most recent version of DBX. Click here for the latest version.
Download topic as PDF

Release notes

New and changed features

Version 3.1.1 of Splunk DB Connect gives you more control over the system’s time zone conversion behavior. You can choose whether or not to convert date and time values read from the source database into the local time zone through the Timezone setting when creating a database connection, and the new localTimezoneConversionEnabled setting in db_connections.conf provides you with two time zone conversion options. For details, see Create a database connection.

Fixed issues

Date resolved Issue number Description
2017-08-22 DBX-4389, DBX-4386 Unindexable fields increase the license usage.
2017-08-13 DBX-4407 Inputs using a rising column with types: datetime, timestamp, date, time cannot be bulk edited after the preview is run
2017-08-07 DBX-4385 Time zone defined on a connection is applied to all time related fields
2017-08-07 DBX-4373, DBX-4372 Lookup with multiple keys does not return results
2017-08-06 DBX-4391, DBX-4378 Index cannot be set without selecting an existing one
2017-07-20 DBX-4381 Audit log file for commands does not rotate

Known issues

Date filed Issue number Description
2018-08-22 DBX-4638 Empty host on the connection and the input will fail the input
2018-08-22 DBX-4637 HEC error message is not logged
2018-06-01 DBX-4616 Need to add extra backlash (escape) in GUI to be able to get literal backslash in query, but this breaks the query in the configuration file, preventing it from running after saving

Create query using GUI, then edit after in configuration file to remove extra backslash


2018-04-18 DBX-4603 On Windows systems, hitting debug/refresh endpoint with DB Connect installed makes splunkweb not restart

Restart splunk through services.msc
2018-04-06 DBX-4595 Populating rising column in "New Input" flow in GUI checks against db_connect_create_connection capability

add db_connect_create_connection capability to role that needs to be able to create new inputs
2018-03-27 DBX-4589 java.io.IOException: Push back buffer is full

In some cases reducing the amount of data returned, by limiting the timeframe of returned events in the search will work
2018-03-20 DBX-4588 All source types from props.conf does not show on DBX 3.1.1
2018-03-13 DBX-4585 Output does not work if column's name contains special characters i.e. dot, space

Edit the conf file to wrap the field with the DB quote identifier such as back quote for MySQL or square brackets for SQL Server
2018-01-09 DBX-4527 dbxquery cannot start on Splunk Enterprise 7+ if users set a time zone in their preferences
2017-12-10 DBX-4491 Upgrade third party libraries for CVE-2017-9735 and CVE-2017-7525.
2017-11-30 DBX-4482 Task server listens on all IP addresses
2017-11-22 DBX-4476 Updating DB credentials are not propagated to inputs and outputs
2017-11-14 DBX-4472 rh_healthlog and rh_usage_data are invalid entries in restmap.conf
2017-10-10 DBX-4454 Invalid rising column index value when non-indexable columns are skipped

Remove non-indexable columns from the query. All data that are binary data are non-indexable  such as the following SQL types: TINYBLOB, BLOB, MEDIUMBLOB, LONGBLOB, BINARY, VARBINARY, IMAGE, LOB. This list is not comprehensive because some databases define their own non-standard types.

Cast the column to text format

2017-10-09 DBX-4451, DBX-4434 Pooled connections are not closed when a connection is disabled or deleted
2017-09-08 DBX-4436 dbxquery fails with an OutOfMemoryError when returning large data set i.e. GB of data
2017-07-31 DBX-4400, DBX-4399 Task server cannot start on SHC if captain is static

Switch to dynamic
2017-07-19 DBX-4387 Splunk cannot be restarted via web interface, deployer or deployment server on Windows

Use the CLI or the services control panel (services.msc) to restart Splunk
2016-12-14 DBX-3610 "TIMESTAMP WITH TIME ZONE" and "TIMESTAMP WITH LOCAL TIME ZONE" can not be used in rising column input

Use cast/convert to convert the timestamp with timezone to a timestamp
2016-10-18 DBX-3309 dbxquery command returns misordered columns

This documentation applies to the following versions of Splunk® DB Connect: 3.1.1


Hi Thscheidegger, I have learned more detail on "non-indexable" and updated the workaround for DBX-4454. In short, all data that are binary data are non-indexable such as the following SQL types: TINYBLOB, BLOB, MEDIUMBLOB, LONGBLOB, BINARY, VARBINARY, IMAGE, LOB. This list is not comprehensive because some databases define their own non-standard types.

Jrevell splunk, Splunker
December 13, 2017

Hi Thscheidegger, You raise a good point. I've reached out to our dev team to gather and publish more detail about what non-indexable means.

Jrevell splunk, Splunker
December 12, 2017

DBX-4454, would be useful to clarify what non indexable means.
Trial and error showed us that null values in some fields can be the cause that nothing is read into splunk

December 8, 2017

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters