All Apps and Add-ons

Connection Error with DBConnect to MySQL

BryanScovill
Explorer

For some reason, after a VM event that caused a disruption to my Splunk's connection to downstream DBs, my MySQL connections will no longer connect. They report back "Could not create connection to database server" or ""Host 'XXX' is blocked because of many connection errors;"

Connections to Postgres DBs stayed just fine. And, oddly, we can create a valid MySQL connection via the same server's OS level MySQL client. Logs on the DB side don't even suggest a connection attempt when we try via DB Connect, although the error sort of contradicts that. Logs on the Splunk side don't yield anything useful. All of the searching I've done points at a network level issues, but that doesn't appear to be the case.

DB Connect and the MYSQL driver are all up to date and haven't been changed recently. Anyone have any thoughts on how to proceed?

Thanks.

0 Karma

BryanScovill
Explorer

So, after a lot of digging and involving TAC and getting the case escalated we finally found a solution. It turns out my timelines were off and the root cause was an upgrade of the DB. Splunk's 5.1 driver was failing the handshake with MariaDB 8.0.17 so we went and manually upgrade the Connector/J to 8 and poof! Happy connections again.

The folks at TAC were telling me that the 8 driver was still in testing as part of the DB Connect package and that package wasn't ready yet. They thought the driver update had a good chance of helping so we tried it manually.

It was a real pain of a problem because the DB logs showed nothing at all unless we set debug to 4 and then only a handshake error not tied to any source. And handshake errors show up on other connections that are successful at that level of debug.

Thanks.

0 Karma

jawaharas
Motivator

Try to increase the logging level and check the internal logs (splunk_app_db_connect*.log) to troubleshoot the issue.

Log configuration URL: http://splunk-host:8000/en-GB/app/splunk_app_db_connect/configuration#/settings/logconfiguration

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...