All Apps and Add-ons

Can you help me with my Splunk Db Connect error?: splunkd.log interpretation

rssimonis
New Member

Splunk Enterprise Version:7.2.4.2; Build: fb30470262e3
Splunk DB Connect Version: 3.1.4; Build: 43

I've installed DB Connect and Splunk enterprise on a trial basis.

I've installed the correct jdbc driver for SQl server and was able to define Inputs, connections, and identities.

I've gone into the SQL Explorer and generated queries that I opened in Search in the DB Connect page.

I've even cut-and-pasted the search expression from the Db Connect search page into the Search & Reporting page.

...so far, so good.

However, in the Search and Reporting page, I only see a "Waiting for Data" message in the Data Summary page, and if I click the Data Summary button, I only see a "waiting for results..." message under the Hosts, Sources, and Sourcetypes tabs — I thought I would see the sourcetypes that were generated under DB Connect.

In the splunkd.log, I see the following error msgs:

ERROR ExecProcessor - message from ""C:\Program Files\Splunk\etc\apps\splunk_app_db_connect\windows_x86_64\bin\server.exe"" 15:33:23.311 [main] INFO com.splunk.dbx.utils.TrustManagerUtil - action=load_key_manager_succeed

The following two messages are repeated:

ERROR ExecProcessor - message from ""C:\Program Files\Splunk\etc\apps\splunk_app_db_connect\windows_x86_64\bin\server.exe"" action=default_task_server_not_found

ERROR ExecProcessor - message from ""C:\Program Files\Splunk\etc\apps\splunk_app_db_connect\windows_x86_64\bin\server.exe"" com.splunk.dbx.server.bootstrap.TaskServerStart.startTaskServer(TaskServerStart.java:90)\\com.splunk.dbx.server.bootstrap.TaskServerStart.streamEvents(TaskServerStart.java:72)\\com.splunk.modularinput.Script.run(Script.java:66)\\com.splunk.modularinput.Script.run(Script.java:44)\\com.splunk.dbx.server.bootstrap.TaskServerStart.main(TaskServerStart.java:150)\\

I believe there is a configuration problem, but I can't find where to look for it, or frankly, what it might be..

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...