All Apps and Add-ons

Splunk DB Connect and Snowflake Integration

titchynz
New Member

Hi All, 

I have searched the community threads for posts similar to this, but none have quite addressed the issue I am seeing. 

I have Splunk Cloud 9.1.2 and would like to retrieve logging from Snowflake. 

Following this snowflake integration blog I have installed the Splunk DB Connect app (3.15.0) and the Splunk DXB Add-on for Snowflake JDBC (1.2.1). (using the self-service app install process on Victoria experience)

When creating the identity in Splunk (matching the user created in Snowflake) this works fine, however creating the connection fails to validate (after trying for approximately 4-5 minutes) and gives me the following non-descript error: 

connection string: 

 

 

jdbc‌‌‌‌:snowflake://<account>.<region>.snowflakecomputing.com/?user=SPLUNK_USER&db=SNOWFLAKE&role=SPLUNK_ROLE&application=SPLUNK

 

 

Output:

Splunk_DB_CONNECT_SNOWFLAKE_CONNECTION_ERROR.png
In the logs I can see slightly more: 

 

2024-02-26 00:59:26.501 +0000 [dw-868 - GET /api/connections/SnowflakeUser/status] INFO com.splunk.dbx.connector.logger.AuditLogger - operation=validation connection_name=SnowflakeUser stanza_name= state=error sql='SELECT current_date()' message='JDBC driver: query has been canceled by user.'

 

This appears to hit some sort of timeout for the JDBC driver.

The other thing I can see is the stanza appears to be blank in this result. However the default Snowflake stanza in the DB connect app matches the stanza created in the Snowflake blogpost. 

Any troubleshooting help would be much appreciated. 

Labels (3)
0 Karma

sourabg
Loves-to-Learn Everything

hello @AaronJaques @titchynz ,

I have posted solution that should resolve the error you have mentioned. Please check the following link 

Stack Overflow - Splunk DB Connect and Snowflake Integration Error

0 Karma

AaronJaques
New Member

Hi @titchynz , was wondering if you found a solution for this.  We are experiencing the exact same thing verbatim and was hoping perhaps you'd done all of the hard work 🙂 and have a solution that you could share. Thanks!

0 Karma

titchynz
New Member

Another sign something is not right - when I construct the database query as described in the Snowflake Integration blog post the resulting SQL string is completely malformed.

 

SQL string from the integration post: 

SQL String from blog post.png

SQL string results when I select the same options: 

malformed SQL string.png

I am able to construct the SQL string using the selection options, however each selection takes another 4-5min to load. 

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...