<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Database lookup during search returning error 1 and error 47 in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Database-lookup-during-search-returning-error-1-and-error-47/m-p/286317#M86693</link>
    <description>&lt;P&gt;I apologize - I'm a Splunk newbie and my Splunk sysadmin won't answer any questions and says the problem isn't with Splunk (I obviously suspect otherwise).&lt;/P&gt;

&lt;P&gt;I have created a database lookup. The credentials used are verified good. I know that Splunk is able to talk to the database, as it is able to pre-fill the database column names.  But every time I try to run a search with the lookup command, it generates two warnings &lt;EM&gt;"Script for lookup table 'LOOKUP NAME' returned error code 47.  Results may be incorrect."&lt;/EM&gt;  And the same with error code 1.&lt;/P&gt;

&lt;P&gt;Based on other threads here, I tried running &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal sourcetype=dbx_debug severity=ERROR OR severity=FATAL
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;and that returned nothing. Stripping out the severity returned 27 records for the past 15 minutes, all of which look normal.&lt;/P&gt;

&lt;P&gt;I've created a clone of the database lookup with a CSV, and when I run the same search, but substitute the file system lookup for the database lookup, it works fine.  Did I simply mis-configure the database lookup somehow?&lt;/P&gt;

&lt;P&gt;I know that the table will return &amp;gt;10,000 rows (about 14,700 specifically) - is that the problem?&lt;/P&gt;

&lt;P&gt;What else can I do to troubleshoot, assuming I don't have access to the Splunk file system?&lt;/P&gt;

&lt;P&gt;Thanks in advance for your suggestions!&lt;/P&gt;</description>
    <pubDate>Thu, 07 Apr 2016 21:38:34 GMT</pubDate>
    <dc:creator>vysean</dc:creator>
    <dc:date>2016-04-07T21:38:34Z</dc:date>
    <item>
      <title>Database lookup during search returning error 1 and error 47</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Database-lookup-during-search-returning-error-1-and-error-47/m-p/286317#M86693</link>
      <description>&lt;P&gt;I apologize - I'm a Splunk newbie and my Splunk sysadmin won't answer any questions and says the problem isn't with Splunk (I obviously suspect otherwise).&lt;/P&gt;

&lt;P&gt;I have created a database lookup. The credentials used are verified good. I know that Splunk is able to talk to the database, as it is able to pre-fill the database column names.  But every time I try to run a search with the lookup command, it generates two warnings &lt;EM&gt;"Script for lookup table 'LOOKUP NAME' returned error code 47.  Results may be incorrect."&lt;/EM&gt;  And the same with error code 1.&lt;/P&gt;

&lt;P&gt;Based on other threads here, I tried running &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal sourcetype=dbx_debug severity=ERROR OR severity=FATAL
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;and that returned nothing. Stripping out the severity returned 27 records for the past 15 minutes, all of which look normal.&lt;/P&gt;

&lt;P&gt;I've created a clone of the database lookup with a CSV, and when I run the same search, but substitute the file system lookup for the database lookup, it works fine.  Did I simply mis-configure the database lookup somehow?&lt;/P&gt;

&lt;P&gt;I know that the table will return &amp;gt;10,000 rows (about 14,700 specifically) - is that the problem?&lt;/P&gt;

&lt;P&gt;What else can I do to troubleshoot, assuming I don't have access to the Splunk file system?&lt;/P&gt;

&lt;P&gt;Thanks in advance for your suggestions!&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2016 21:38:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Database-lookup-during-search-returning-error-1-and-error-47/m-p/286317#M86693</guid>
      <dc:creator>vysean</dc:creator>
      <dc:date>2016-04-07T21:38:34Z</dc:date>
    </item>
    <item>
      <title>Re: Database lookup during search returning error 1 and error 47</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Database-lookup-during-search-returning-error-1-and-error-47/m-p/286318#M86694</link>
      <description>&lt;P&gt;I have the exact same issue. The only 'solution' I find relates to a double \ for the db server which I do not have. What is error code 47 ? It must have a description ?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2016 12:22:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Database-lookup-during-search-returning-error-1-and-error-47/m-p/286318#M86694</guid>
      <dc:creator>jasonbew</dc:creator>
      <dc:date>2016-04-11T12:22:30Z</dc:date>
    </item>
    <item>
      <title>Re: Database lookup during search returning error 1 and error 47</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Database-lookup-during-search-returning-error-1-and-error-47/m-p/286319#M86695</link>
      <description>&lt;P&gt;I gave up on this.  &lt;/P&gt;

&lt;P&gt;Thanks to this thread (and specifically &lt;STRONG&gt;jpass&lt;/STRONG&gt;'s response):  &lt;A href="https://answers.splunk.com/answers/79893/dbconnect-can-we-populate-a-lookup-table-from-database-data-on-a-period-basis.html"&gt;https://answers.splunk.com/answers/79893/dbconnect-can-we-populate-a-lookup-table-from-database-data-on-a-period-basis.html&lt;/A&gt;, I've configured a periodic CSV dump out of the database, which is probably a more efficient method anyway, given the relatively infrequent data changes.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2016 15:22:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Database-lookup-during-search-returning-error-1-and-error-47/m-p/286319#M86695</guid>
      <dc:creator>vysean</dc:creator>
      <dc:date>2016-04-11T15:22:01Z</dc:date>
    </item>
    <item>
      <title>Re: Database lookup during search returning error 1 and error 47</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Database-lookup-during-search-returning-error-1-and-error-47/m-p/286320#M86696</link>
      <description>&lt;P&gt;I have the exact same problem...but my DB contains more than 30 millions entries...a CSV dump is not an option...&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2016 09:08:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Database-lookup-during-search-returning-error-1-and-error-47/m-p/286320#M86696</guid>
      <dc:creator>tpaulsen</dc:creator>
      <dc:date>2016-09-13T09:08:51Z</dc:date>
    </item>
  </channel>
</rss>

