I'm trying to set up the Splunk DB Connect 2 App.
I have a valid user that can make a select operation on a particular table, tested via SQL directly.
If I try the same query using the "Query" tab on my Connection, using "Advanced query mode" the App returns:
External search command 'dbxquery' returned error code 1. Script output = " ERROR "Exception at ""/opt/splunk/etc/apps/splunk_app_db_connect/bin/dbxquery.py"", line 123 : No rpc server enabled" "
Can anyone help me?
Check your SQL server logs for more details...
Are there any attempts to connect as the username you have provided db connect 2 with?
If so, then surely there is an error associated with the connection. What is the error?
If no records exists in SQL log, are there any in eventvwr.msc? Try application,system, and security logs. You're looking for any activity coming from the splunk server that has db connect.
I look the Oracle log files (alert.log) and network (listener.log) but no errors was found at the connection moment.
Can you check the following path/stanza and verify that the disabled flag is set to 0?
The version that comes with Splunk is the baseline. This issue does not reside with the python script itself but rather with an incorrectly enabled inputs.conf flag as seen in the below answer.