All Apps and Add-ons

DB Connect 2: DBoutput tests OK, but why does the scheduled output fail to insert search results in the database with an "Unauthorized" error in dbx2.log?

jkleensang
Path Finder

Fresh install of DB Connect 2 (2.1.2) on Splunk Enterprise search head (6.3.1). We've been able to configure a Connection, Identity, and an Output and everything tests fine. However, the scheduled db output fails to insert the search results in to the database. The only error is in the dbx2.log:

02/03/2016 15:00:02 [CRITICAL] [mi_output.py] HTTP Error 401: Unauthorized

I can't find any denials in audittrail. No related errors show up in any of the internal indexes. From what I can tell, the dboutput runs as "admin", which has all perms. None of the app permissions have been changed from their default(s).

Has anyone seen this before? I feel there's something obvious I'm missing....

0 Karma
1 Solution

jkleensang
Path Finder

This issue seems to be resolved. I had upgraded sa-ldapsearch to 2.1.3, but that didn't fix the problem. Then I upgraded splunk to 6.4.0 and didn't think it had resolved the issue, but didn't realize that the scheduled search using this connection had been disabled. When I got back around to troubleshooting this issue, I re-enabled it and everything now works as expected. Not an answer, but at least resolution!

View solution in original post

0 Karma

jkleensang
Path Finder

This issue seems to be resolved. I had upgraded sa-ldapsearch to 2.1.3, but that didn't fix the problem. Then I upgraded splunk to 6.4.0 and didn't think it had resolved the issue, but didn't realize that the scheduled search using this connection had been disabled. When I got back around to troubleshooting this issue, I re-enabled it and everything now works as expected. Not an answer, but at least resolution!

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...