<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk DB connect DBX Query error in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-DB-connect-DBX-Query-error/m-p/404558#M4664</link>
    <description>&lt;P&gt;You said "one specific connection". Can you run other queries against that 'connection'?&lt;/P&gt;</description>
    <pubDate>Wed, 28 Nov 2018 15:44:36 GMT</pubDate>
    <dc:creator>joebisesi</dc:creator>
    <dc:date>2018-11-28T15:44:36Z</dc:date>
    <item>
      <title>Splunk DB connect DBX Query error</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-DB-connect-DBX-Query-error/m-p/404554#M4660</link>
      <description>&lt;P&gt;Dear all ,&lt;/P&gt;

&lt;P&gt;I have splunk db connect and using many input connections successfully.One specific connection throws this error &lt;/P&gt;

&lt;P&gt;Error in 'dbxquery' command: External search command exited unexpectedly with non-zero error code 1. &lt;/P&gt;

&lt;P&gt;/****** Script for SelectTopNRows command from SSMS  ******/&lt;BR /&gt;
SELECT TOP 1000 [NUMBER]&lt;BR /&gt;
      ,[OPEN]&lt;BR /&gt;
      ,[CATEGORY]&lt;BR /&gt;
      ,[SUBCATEGORY]&lt;BR /&gt;
      ,[MODEL]&lt;BR /&gt;
      ,[CURRENT_PHASE]&lt;BR /&gt;
      ,[IMPACT]&lt;BR /&gt;
      ,[STATUS]&lt;BR /&gt;
      ,[PRIORITY]&lt;BR /&gt;
      ,[APPROVAL_STATUS]&lt;BR /&gt;
      ,[ALERT]&lt;BR /&gt;
      ,[ALERT_NAMES]&lt;BR /&gt;
      ,[PENDING_GROUPS]&lt;BR /&gt;
      ,[REASON]&lt;BR /&gt;
      ,[SUBMIT_DATE]&lt;BR /&gt;
      ,[UPDATE_DATE]&lt;BR /&gt;
      ,[CLOSE_DATE]&lt;BR /&gt;
      ,[CANCELLED_DATE]&lt;BR /&gt;
      ,[REQUESTOR_NAME]&lt;BR /&gt;
      ,[COORDINATOR_NAME]&lt;BR /&gt;
      ,[COORDINATOR_DEPT]&lt;BR /&gt;
      ,[ASSIGNED_TO]&lt;BR /&gt;
      ,[SHIP_TO_CODE]&lt;BR /&gt;
      ,[BILL_TO_CODE]&lt;BR /&gt;
      ,[TOTAL_COST]&lt;BR /&gt;
      ,[BILL_TO_EXT]&lt;BR /&gt;
      ,[SHIP_TO_EXT]&lt;BR /&gt;
      ,[PROJECT_ID]&lt;BR /&gt;
      ,[PLANNED_START]&lt;BR /&gt;
      ,[PLANNED_END]&lt;BR /&gt;
      ,[REQUESTED_FOR]&lt;BR /&gt;
      ,[BRIEF_DESCRIPTION]&lt;BR /&gt;
      ,[FUTURE_GROUPS]&lt;BR /&gt;
      ,[APPROVED_GROUPS]&lt;BR /&gt;
      ,[BILL_TO_DEPT]&lt;BR /&gt;
      ,[COMPANY]&lt;BR /&gt;
      ,[ALERT_STATUS]&lt;BR /&gt;
      ,[SVC_OPTIONS]&lt;BR /&gt;
      ,[FOLDER]&lt;BR /&gt;
      ,[SLA_BREACH]&lt;BR /&gt;
      ,[NEXT_BREACH]&lt;BR /&gt;
      ,[SVCCARTID]&lt;BR /&gt;
      ,[AGREEMENT_IDS]&lt;BR /&gt;
      ,[ASSIGNED_GROUP]&lt;BR /&gt;
      ,[UPDATE_ACTION]&lt;BR /&gt;
      ,[CUST_VISIBLE]&lt;BR /&gt;
      ,[CLOSURE_CODE]&lt;BR /&gt;
      ,[CLOSURE_COMMENTS]&lt;BR /&gt;
      ,[DELIVERY_DATE]&lt;BR /&gt;
      ,[COST_CURRENCY_CODE]&lt;BR /&gt;
      ,[CLOSED_BY]&lt;BR /&gt;
      ,[DESCRIPTION]&lt;BR /&gt;
      ,[GLOBAL_LEAD_TIME]&lt;BR /&gt;
      ,[REQUESTED_DATE]&lt;BR /&gt;
      ,[MODELNAME]&lt;BR /&gt;
      ,[SYSMODTIME]&lt;BR /&gt;
      ,[SYSMODUSER]&lt;BR /&gt;
      ,[SYSMODCOUNT]&lt;BR /&gt;
      ,[SEVERITY]&lt;BR /&gt;
      ,[OPENED_BY]&lt;BR /&gt;
      ,[AFFECTED_ITEM]&lt;BR /&gt;
      ,[LOGICAL_NAME]&lt;BR /&gt;
      ,[ESCALATED]&lt;BR /&gt;
      ,[OWNER]&lt;BR /&gt;
      ,[LABOR]&lt;BR /&gt;
      ,[FOREIGN_ID]&lt;BR /&gt;
      ,[OTRSREFERENCENUMBER]&lt;BR /&gt;
      ,[LASTASSIGNMENTGROUP]&lt;BR /&gt;
      ,[REFERENCE_ID]&lt;BR /&gt;
      ,[TICKET_TYPE]&lt;BR /&gt;
      ,[OTRSINTERFACE]&lt;BR /&gt;
      ,[ATTACHDATA]&lt;BR /&gt;
      ,[ATTACHFILENAME]&lt;BR /&gt;
      ,[LANGUAGE]&lt;BR /&gt;
      ,[FULFILMENT_DATEOLY]&lt;BR /&gt;
      ,[REQUEST_SUBSTATUS]&lt;BR /&gt;
      ,[ATTACHMENTLOCATION]&lt;BR /&gt;
      ,[OTRSFILENAME]&lt;BR /&gt;
      ,[OTRSFILENAMES]&lt;BR /&gt;
      ,[INCIDENT_ID]&lt;BR /&gt;
      ,[REQVIPUSER]&lt;BR /&gt;
      ,[EUCDEVICETYPE]&lt;BR /&gt;
      ,[OSTEREFERENCENUMBER]&lt;BR /&gt;
      ,[UPDATEACTION]&lt;BR /&gt;
      ,[KPF_ID]&lt;BR /&gt;
      ,[BACKTOFULFILLDATE]&lt;BR /&gt;
      ,[BACKTOFULFILL]&lt;BR /&gt;
      ,[OLY_TTR]&lt;BR /&gt;
      ,[OLY_IO_OFFICER]&lt;BR /&gt;
      ,[OLY_SALES_OFFICER]&lt;BR /&gt;
      ,[OLY_COUNTRY]&lt;BR /&gt;
      ,[OLY_ORIGIN]&lt;BR /&gt;
      ,[OLY_FIELD_TECHNICIAN]&lt;BR /&gt;
      ,[OLY_FIELD_TECHNICIAN1]&lt;BR /&gt;
      ,[OLY_BACKTOFULFILL_LIST]&lt;BR /&gt;
  FROM [servicemanager].[dbo].[REQUESTM1] where SYSMODTIME &amp;gt; ? ORDER BY SYSMODTIME ASC&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:08:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-DB-connect-DBX-Query-error/m-p/404554#M4660</guid>
      <dc:creator>anitaroseline</dc:creator>
      <dc:date>2020-09-29T22:08:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB connect DBX Query error</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-DB-connect-DBX-Query-error/m-p/404555#M4661</link>
      <description>&lt;P&gt;Have you checked the dbx logs?  Do the logs on the DB side shed any light on the problem?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Nov 2018 12:54:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-DB-connect-DBX-Query-error/m-p/404555#M4661</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2018-11-27T12:54:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB connect DBX Query error</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-DB-connect-DBX-Query-error/m-p/404556#M4662</link>
      <description>&lt;P&gt;No such errors found.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Nov 2018 07:09:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-DB-connect-DBX-Query-error/m-p/404556#M4662</guid>
      <dc:creator>anitaroseline</dc:creator>
      <dc:date>2018-11-28T07:09:22Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB connect DBX Query error</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-DB-connect-DBX-Query-error/m-p/404557#M4663</link>
      <description>&lt;P&gt;The same query works well while i run in sql studio&lt;/P&gt;</description>
      <pubDate>Wed, 28 Nov 2018 10:43:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-DB-connect-DBX-Query-error/m-p/404557#M4663</guid>
      <dc:creator>anitaroseline</dc:creator>
      <dc:date>2018-11-28T10:43:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB connect DBX Query error</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-DB-connect-DBX-Query-error/m-p/404558#M4664</link>
      <description>&lt;P&gt;You said "one specific connection". Can you run other queries against that 'connection'?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Nov 2018 15:44:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-DB-connect-DBX-Query-error/m-p/404558#M4664</guid>
      <dc:creator>joebisesi</dc:creator>
      <dc:date>2018-11-28T15:44:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB connect DBX Query error</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-DB-connect-DBX-Query-error/m-p/404559#M4665</link>
      <description>&lt;P&gt;Have you tried that query in the SQL Explorer tab on your DB Connect?  I found that when I was having problems, running the query there helped me troubleshoot.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Nov 2018 18:49:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-DB-connect-DBX-Query-error/m-p/404559#M4665</guid>
      <dc:creator>reswob4</dc:creator>
      <dc:date>2018-11-28T18:49:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB connect DBX Query error</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-DB-connect-DBX-Query-error/m-p/404560#M4666</link>
      <description>&lt;P&gt;Yes i did and same error persists&lt;/P&gt;</description>
      <pubDate>Fri, 30 Nov 2018 12:07:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-DB-connect-DBX-Query-error/m-p/404560#M4666</guid>
      <dc:creator>anitaroseline</dc:creator>
      <dc:date>2018-11-30T12:07:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB connect DBX Query error</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-DB-connect-DBX-Query-error/m-p/404561#M4667</link>
      <description>&lt;P&gt;yes it works&lt;/P&gt;</description>
      <pubDate>Mon, 03 Dec 2018 06:23:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-DB-connect-DBX-Query-error/m-p/404561#M4667</guid>
      <dc:creator>anitaroseline</dc:creator>
      <dc:date>2018-12-03T06:23:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB connect DBX Query error</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-DB-connect-DBX-Query-error/m-p/404562#M4668</link>
      <description>&lt;P&gt;I'm working with Splunk Support on a similar issue.  One suggestion they made to help troubleshoot is to run the query from the Search window.&lt;/P&gt;

&lt;P&gt;Here's a copy of the instructions they sent me:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| dbxquery query="LONG_QUERY" connection="YOUR_CONNECTION_NAME" timeout=6000

The easiest way to do this is to hit the “Open In Search” button on the SQL Explorer screen after you have written out the full query (the button is to the upper right corner). When the query opens on the next page just add timeout=6000 to the search as shown above.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;As you probably can guess, this will enable you to test different portions of your query quickly.  I'm using it to try and narrow down which part of my query is giving me trouble.  &lt;/P&gt;

&lt;P&gt;You can add or subtract or remove the timeout part......&lt;/P&gt;</description>
      <pubDate>Fri, 07 Dec 2018 20:57:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-DB-connect-DBX-Query-error/m-p/404562#M4668</guid>
      <dc:creator>reswob4</dc:creator>
      <dc:date>2018-12-07T20:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB connect DBX Query error</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-DB-connect-DBX-Query-error/m-p/538603#M9677</link>
      <description>&lt;P&gt;I have the same issue, but for all connections, "&lt;SPAN&gt;Error in 'dbxquery' command: External search command exited unexpectedly with non-zero error code 1.&lt;/SPAN&gt;" Splunk is indexing already existing database inputs (from MySQL), I am not able to add any new input because of this failure.&amp;nbsp; I could not find any records in log files so I do not have a clue what I can change to fix it....&lt;/P&gt;</description>
      <pubDate>Thu, 04 Feb 2021 12:43:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-DB-connect-DBX-Query-error/m-p/538603#M9677</guid>
      <dc:creator>rapmancz</dc:creator>
      <dc:date>2021-02-04T12:43:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB connect DBX Query error</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-DB-connect-DBX-Query-error/m-p/544940#M9806</link>
      <description>&lt;P&gt;Hi, had the same problem.&amp;nbsp; After weeks of troubleshooting I found following entry under default/commands.conf&lt;/P&gt;&lt;P&gt;####### uncomment following lines to revert dbxquery to 3.2.0 version&lt;BR /&gt;# [dbxquery]&lt;BR /&gt;# run_in_preview = false&lt;BR /&gt;# filename = java.path&lt;BR /&gt;# chunked = true&lt;BR /&gt;# command.arg.1 = -Dlogback.configurationFile=../config/command_logback.xml&lt;BR /&gt;# command.arg.2 = -DDBX_COMMAND_LOG_LEVEL=INFO&lt;BR /&gt;# command.arg.3 = -cp&lt;BR /&gt;# command.arg.4 = ../jars/dbxquery.jar&lt;BR /&gt;# command.arg.5 = com.splunk.dbx.command.DbxQueryCommand&lt;/P&gt;&lt;P&gt;Gave it&amp;nbsp; a try and copied all over to local/commands.conf and it works.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Mar 2021 14:21:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-DB-connect-DBX-Query-error/m-p/544940#M9806</guid>
      <dc:creator>hpbrand</dc:creator>
      <dc:date>2021-03-23T14:21:45Z</dc:date>
    </item>
  </channel>
</rss>

