<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: search head cluster after splunk db connect ver 3.1.1 Error related in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/search-head-cluster-after-splunk-db-connect-ver-3-1-1-Error/m-p/375987#M7796</link>
    <description>&lt;P&gt;hello there,&lt;/P&gt;

&lt;P&gt;please read the doc in detail:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/DBX/3.1.3/DeployDBX/Architectureandperformanceconsiderations"&gt;http://docs.splunk.com/Documentation/DBX/3.1.3/DeployDBX/Architectureandperformanceconsiderations&lt;/A&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;To use Splunk DB Connect in a distributed search environment, including search head clusters, you must determine the planned use cases. For ad hoc, interactive usage of database connections by live users, install the app on search head(s). For scheduled indexing from databases and output of data to databases, install the app on heavy forwarder(s). 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;avoid installing DB Connect as an input (data collection) mechanism in a Search Head Cluster. keep it on a single Splunk instance only, preferably a Heavy Forwarder.&lt;/P&gt;

&lt;P&gt;hope it helps&lt;/P&gt;</description>
    <pubDate>Tue, 08 May 2018 01:35:06 GMT</pubDate>
    <dc:creator>adonio</dc:creator>
    <dc:date>2018-05-08T01:35:06Z</dc:date>
    <item>
      <title>search head cluster after splunk db connect ver 3.1.1 Error related</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/search-head-cluster-after-splunk-db-connect-ver-3-1-1-Error/m-p/375986#M7795</link>
      <description>&lt;P&gt;hi &lt;BR /&gt;
I installed it by the method presented from the link below.&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/DBX/3.1.1/DeployDBX/Distributeddeployment" target="_blank"&gt;http://docs.splunk.com/Documentation/DBX/3.1.1/DeployDBX/Distributeddeployment&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;The following error occurs.&lt;BR /&gt;
" Unable to initialize modular input "server" defined inside the app "splunk_app_db_connect": Introspecting scheme=server: Unable to run "/opt/splunk/etc/apps/splunk_app_db_connect/linux_x86_64/bin/server.sh --scheme": child failed to start: Permission denied "&lt;/P&gt;

&lt;P&gt;I set only identities and connections, mysql JDBC drivers&lt;/P&gt;

&lt;P&gt;What should I do?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:22:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/search-head-cluster-after-splunk-db-connect-ver-3-1-1-Error/m-p/375986#M7795</guid>
      <dc:creator>spl109</dc:creator>
      <dc:date>2020-09-29T19:22:27Z</dc:date>
    </item>
    <item>
      <title>Re: search head cluster after splunk db connect ver 3.1.1 Error related</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/search-head-cluster-after-splunk-db-connect-ver-3-1-1-Error/m-p/375987#M7796</link>
      <description>&lt;P&gt;hello there,&lt;/P&gt;

&lt;P&gt;please read the doc in detail:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/DBX/3.1.3/DeployDBX/Architectureandperformanceconsiderations"&gt;http://docs.splunk.com/Documentation/DBX/3.1.3/DeployDBX/Architectureandperformanceconsiderations&lt;/A&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;To use Splunk DB Connect in a distributed search environment, including search head clusters, you must determine the planned use cases. For ad hoc, interactive usage of database connections by live users, install the app on search head(s). For scheduled indexing from databases and output of data to databases, install the app on heavy forwarder(s). 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;avoid installing DB Connect as an input (data collection) mechanism in a Search Head Cluster. keep it on a single Splunk instance only, preferably a Heavy Forwarder.&lt;/P&gt;

&lt;P&gt;hope it helps&lt;/P&gt;</description>
      <pubDate>Tue, 08 May 2018 01:35:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/search-head-cluster-after-splunk-db-connect-ver-3-1-1-Error/m-p/375987#M7796</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2018-05-08T01:35:06Z</dc:date>
    </item>
    <item>
      <title>Re: search head cluster after splunk db connect ver 3.1.1 Error related</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/search-head-cluster-after-splunk-db-connect-ver-3-1-1-Error/m-p/375988#M7797</link>
      <description>&lt;P&gt;Thank you. &lt;BR /&gt;
SHC tries to install to use the |dbxout command.&lt;/P&gt;

&lt;P&gt;Is there no way to resolve the error? The splunk version is 6.6.3&lt;/P&gt;</description>
      <pubDate>Wed, 09 May 2018 22:14:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/search-head-cluster-after-splunk-db-connect-ver-3-1-1-Error/m-p/375988#M7797</guid>
      <dc:creator>spl109</dc:creator>
      <dc:date>2018-05-09T22:14:16Z</dc:date>
    </item>
    <item>
      <title>Re: search head cluster after splunk db connect ver 3.1.1 Error related</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/search-head-cluster-after-splunk-db-connect-ver-3-1-1-Error/m-p/375989#M7798</link>
      <description>&lt;P&gt;mine is on a heavy forwarder.  this just started happening&lt;/P&gt;

&lt;P&gt;Unable to initialize modular input "server" defined inside the app "splunk_app_db_connect": Introspecting scheme=server: Unable to run "/opt/splunk/etc/apps/splunk_app_db_connect/linux_x86_64/bin/server.sh --scheme": child failed to start: Permission denied &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 21:56:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/search-head-cluster-after-splunk-db-connect-ver-3-1-1-Error/m-p/375989#M7798</guid>
      <dc:creator>jaxjohnny2000</dc:creator>
      <dc:date>2020-09-29T21:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: search head cluster after splunk db connect ver 3.1.1 Error related</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/search-head-cluster-after-splunk-db-connect-ver-3-1-1-Error/m-p/375990#M7799</link>
      <description>&lt;P&gt;My answer was to change the permissions on the server.sh file to make it and executable.&lt;/P&gt;

&lt;P&gt;chmod 777 server.sh&lt;/P&gt;</description>
      <pubDate>Wed, 07 Nov 2018 20:49:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/search-head-cluster-after-splunk-db-connect-ver-3-1-1-Error/m-p/375990#M7799</guid>
      <dc:creator>jaxjohnny2000</dc:creator>
      <dc:date>2018-11-07T20:49:43Z</dc:date>
    </item>
  </channel>
</rss>

