<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why are we getting this error after upgrading Splunk DB Connect? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-are-we-getting-this-error-after-upgrading-Splunk-DB-Connect/m-p/625476#M14913</link>
    <description>&lt;P&gt;Did you ever find a solution for this issue?&lt;/P&gt;</description>
    <pubDate>Thu, 29 Dec 2022 14:23:35 GMT</pubDate>
    <dc:creator>coreyCLI</dc:creator>
    <dc:date>2022-12-29T14:23:35Z</dc:date>
    <item>
      <title>Why are we getting this error after upgrading Splunk DB Connect?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-are-we-getting-this-error-after-upgrading-Splunk-DB-Connect/m-p/586641#M11680</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;02-24-2022 21:24:10.711 INFO ScopedTimer [9796 searchOrchestrator] - search.optimize 0.030224023 02-24-2022 21:24:10.711 INFO SearchPhaseGenerator [9796 searchOrchestrator] - Failed to create phases using AST:Error in 'dbxquery' command: External search command exited unexpectedly with non-zero error code 1.. Falling back to 2 phase mode. 02-24-2022 21:24:10.711 INFO SearchPhaseGenerator [9796 searchOrchestrator] - Executing two phase fallback for the search=| dbxquery query="SELECT * FROM \"ngcs2_0\".\"public\".\"responder\"" connection="PROV_DB_WA_2.0" timeout=6000 02-24-2022 21:24:10.711 INFO SearchParser [9796 searchOrchestrator] - PARSING: | dbxquery query="SELECT * FROM \"ngcs2_0\".\"public\".\"responder\"" connection="PROV_DB_WA_2.0" timeout=6000 02-24-2022 21:24:10.712 INFO ChunkedExternProcessor [9796 searchOrchestrator] - Running process: /export/home/splunk/splunk/bin/python3.7 /export/home/splunk/splunk/etc/apps/splunk_app_db_connect/bin/dbxquery_bridge.py 02-24-2022 21:24:10.738 ERROR ChunkedExternProcessor [9807 ChunkedExternProcessorStderrLogger] - stderr: Traceback (most recent call last): 02-24-2022 21:24:10.738 ERROR ChunkedExternProcessor [9807 ChunkedExternProcessorStderrLogger] - stderr: File "/export/home/splunk/splunk/etc/apps/splunk_app_db_connect/bin/dbxquery_bridge.py", line 125, in &amp;lt;module&amp;gt; 02-24-2022 21:24:10.738 ERROR ChunkedExternProcessor [9807 ChunkedExternProcessorStderrLogger] - stderr: main() 02-24-2022 21:24:10.738 ERROR ChunkedExternProcessor [9807 ChunkedExternProcessorStderrLogger] - stderr: File "/export/home/splunk/splunk/etc/apps/splunk_app_db_connect/bin/dbxquery_bridge.py", line 121, in main 02-24-2022 21:24:10.738 ERROR ChunkedExternProcessor [9807 ChunkedExternProcessorStderrLogger] - stderr: bridge = DbxQueryBridge(sys.argv) 02-24-2022 21:24:10.738 ERROR ChunkedExternProcessor [9807 ChunkedExternProcessorStderrLogger] - stderr: File "/export/home/splunk/splunk/etc/apps/splunk_app_db_connect/bin/dbxquery_bridge.py", line 65, in _init_ 02-24-2022 21:24:10.738 ERROR ChunkedExternProcessor [9807 ChunkedExternProcessorStderrLogger] - stderr: self.sock.connect(('localhost', port)) 02-24-2022 21:24:10.738 ERROR ChunkedExternProcessor [9807 ChunkedExternProcessorStderrLogger] - stderr: ConnectionRefusedError: [Errno 111] Connection refused 02-24-2022 21:24:10.741 ERROR ChunkedExternProcessor [9796 searchOrchestrator] - EOF while attempting to read transport header read_size=0 02-24-2022 21:24:10.741 ERROR ChunkedExternProcessor [9796 searchOrchestrator] - Error in 'dbxquery' command: External search command exited unexpectedly with non-zero error code 1. 02-24-2022 21:24:10.741 ERROR SearchPhaseGenerator [9796 searchOrchestrator] - Fallback to two phase search failed:Error in 'dbxquery' command: External search command exited unexpectedly with non-zero error code 1. 02-24-2022 21:24:10.743 ERROR SearchStatusEnforcer [9796 searchOrchestrator] - sid:1645766650.38_B885E1F4-85FA-453C-A035-E8DCD64B223F Error in 'dbxquery' command: External search command exited unexpectedly with non-zero error code 1. 02-24-2022 21:24:10.743 INFO SearchStatusEnforcer [9796 searchOrchestrator] - State changed to FAILED due to: Error in 'dbxquery' command: External search command exited unexpectedly with non-zero error code 1. 02-24-2022 21:24:10.744 INFO SearchStatusEnforcer [9796 searchOrchestrator] - Enforcing disk quota = 10485760000 02-24-2022 21:24:10.747 INFO DispatchStorageManager [9796 searchOrchestrator] - Remote storage disabled for search artifacts. 02-24-2022 21:24:10.747 INFO DispatchManager [9796 searchOrchestrator] - DispatchManager::dispatchHasFinished(id='1645766650.38_B885E1F4-85FA-453C-A035-E8DCD64B223F', username='admin') 02-24-2022 21:24:10.747 INFO UserManager [9796 searchOrchestrator] - Unwound user context: admin -&amp;gt; NULL 02-24-2022 21:24:10.747 INFO SearchStatusEnforcer [9789 RunDispatch] - SearchStatusEnforcer is already terminated 02-24-2022 21:24:10.747 INFO UserManager [9789 RunDispatch] - Unwound user context: admin -&amp;gt; NULL 02-24-2022 21:24:10.747 INFO LookupDataProvider [9789 RunDispatch] - Clearing out lookup shared provider map 02-24-2022 21:24:10.749 ERROR dispatchRunner [28370 MainThread] - RunDispatch::runDispatchThread threw error: Error in 'dbxquery' command: External search command exited unexpectedly with non-zero error code 1.&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 25 Feb 2022 18:10:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-are-we-getting-this-error-after-upgrading-Splunk-DB-Connect/m-p/586641#M11680</guid>
      <dc:creator>rlucier</dc:creator>
      <dc:date>2022-02-25T18:10:51Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we getting this error after upgrading Splunk DB Connect?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Why-are-we-getting-this-error-after-upgrading-Splunk-DB-Connect/m-p/625476#M14913</link>
      <description>&lt;P&gt;Did you ever find a solution for this issue?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Dec 2022 14:23:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Why-are-we-getting-this-error-after-upgrading-Splunk-DB-Connect/m-p/625476#M14913</guid>
      <dc:creator>coreyCLI</dc:creator>
      <dc:date>2022-12-29T14:23:35Z</dc:date>
    </item>
  </channel>
</rss>

