All Apps and Add-ons

[Indexer_Name] Streamed search execute failed because: Error in 'script': Getinfo probe failed for external search command 'dbxquery'

ishaanshekhar
Communicator

alt text

I have SPLUNK 6.3 version and have 4 indexers in the cluster. I installed SPLUNK DB Connect v2 app on the standalone dev SH.

I added a DB connection in the app, which was successfully tested (showed schema names in the preview). Then, I gave read permission to "All Apps" for the SPLUNK DB Connect 2 app (using Manage Apps), the Identity (in DBconnect 2 app), and the DB Connection (in DBconnect 2 app).

However, when I run an adhoc search query in the Search app, I get 4 errors, one for my 4 indexers each indexer.

I am wondering, why the Search app is looking in my indexers? After all, it is an adhoc db query.

P.S. The Splunk DB Connect 2 app is only installed in my standalone dev SH, not on the Indexers.

Please help!

Thanks
Ishaan

1 Solution

jcoates_splunk
Splunk Employee
Splunk Employee

per todd_miller, this is a newly introduced bug -- please open a support ticket so we can be sure to update you on the fix.

View solution in original post

jcoates_splunk
Splunk Employee
Splunk Employee

per todd_miller, this is a newly introduced bug -- please open a support ticket so we can be sure to update you on the fix.

ishaanshekhar
Communicator

Thanks a lot, @jcoates_splunk !

I updated to 2.0.6 and it is working fine now 🙂

Regards,
Ishaan

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

todd_miller
Communicator

I think a few people are getting this error (myself included) but just for due-diligence, please check your 'commands.conf' file in the DBXv2 "default" directory and make sure that local is set to true. I don't think it matters but it's still worth validating.

0 Karma

ishaanshekhar
Communicator

Not working; (It is set to true already).
$ pwd
SPLUNK_HOME/etc/apps/splunk_app_db_connect/default
$ cat commands.conf
[dbxquery]
filename = dbxquery.py
supports_getinfo = true
supports_rawargs = true
passauth = true
run_in_preview = false
local = true

Any other suggestion, please!

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...