One or more Splunk data source query jobs are failing and returning a 404 error code in the Splunk importer log. The SQL Server Agent indicates job failure with an error code of 170.
Release : 6.x
Component : Splunk Import Utility
The job failure is caused by an incorrect Splunk Application Name.
Correct the Splunk Application Name field in the failing job's data source query by following this procedure:
The Splunk importer logs are located in the following path on the server hosting the Risk Fabric Database Utilities:
%ProgramData%\BayDynamics\Logs
The importer log files use the following naming conventions:
IW_SplunkImporter.<yyyyMMdd>.log
SplunkImporter.<yyyyMMdd>.log
SplunkImporterSplunkResultsDriven_<ID>.<yyyyMMdd>.log
Splunk data source query jobs are identified in SQL Server Management Studio (SSMS) under SQL Server Agent > Jobs by the following naming convention:
RiskFabric_IW_DataSourceQueryID_<ID>