All Apps and Add-ons

DB Connect 2: DBoutput tests OK, but why does the scheduled output fail to insert search results in the database with an "Unauthorized" error in dbx2.log?

jkleensang
Path Finder

Fresh install of DB Connect 2 (2.1.2) on Splunk Enterprise search head (6.3.1). We've been able to configure a Connection, Identity, and an Output and everything tests fine. However, the scheduled db output fails to insert the search results in to the database. The only error is in the dbx2.log:

02/03/2016 15:00:02 [CRITICAL] [mi_output.py] HTTP Error 401: Unauthorized

I can't find any denials in audittrail. No related errors show up in any of the internal indexes. From what I can tell, the dboutput runs as "admin", which has all perms. None of the app permissions have been changed from their default(s).

Has anyone seen this before? I feel there's something obvious I'm missing....

0 Karma
1 Solution

jkleensang
Path Finder

This issue seems to be resolved. I had upgraded sa-ldapsearch to 2.1.3, but that didn't fix the problem. Then I upgraded splunk to 6.4.0 and didn't think it had resolved the issue, but didn't realize that the scheduled search using this connection had been disabled. When I got back around to troubleshooting this issue, I re-enabled it and everything now works as expected. Not an answer, but at least resolution!

View solution in original post

0 Karma

jkleensang
Path Finder

This issue seems to be resolved. I had upgraded sa-ldapsearch to 2.1.3, but that didn't fix the problem. Then I upgraded splunk to 6.4.0 and didn't think it had resolved the issue, but didn't realize that the scheduled search using this connection had been disabled. When I got back around to troubleshooting this issue, I re-enabled it and everything now works as expected. Not an answer, but at least resolution!

0 Karma
Get Updates on the Splunk Community!

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...

Get ready to show some Splunk Certification swagger at .conf24!

Dive into the deep end of data by earning a Splunk Certification at .conf24. We're enticing you again this ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Now On-Demand Join us to learn more about how you can leverage Service Level Objectives (SLOs) and the new ...