All Apps and Add-ons

Splunk DB Connect and Snowflake Integration

titchynz
New Member

Hi All, 

I have searched the community threads for posts similar to this, but none have quite addressed the issue I am seeing. 

I have Splunk Cloud 9.1.2 and would like to retrieve logging from Snowflake. 

Following this snowflake integration blog I have installed the Splunk DB Connect app (3.15.0) and the Splunk DXB Add-on for Snowflake JDBC (1.2.1). (using the self-service app install process on Victoria experience)

When creating the identity in Splunk (matching the user created in Snowflake) this works fine, however creating the connection fails to validate (after trying for approximately 4-5 minutes) and gives me the following non-descript error: 

connection string: 

 

 

jdbc‌‌‌‌:snowflake://<account>.<region>.snowflakecomputing.com/?user=SPLUNK_USER&db=SNOWFLAKE&role=SPLUNK_ROLE&application=SPLUNK

 

 

Output:

Splunk_DB_CONNECT_SNOWFLAKE_CONNECTION_ERROR.png
In the logs I can see slightly more: 

 

2024-02-26 00:59:26.501 +0000 [dw-868 - GET /api/connections/SnowflakeUser/status] INFO com.splunk.dbx.connector.logger.AuditLogger - operation=validation connection_name=SnowflakeUser stanza_name= state=error sql='SELECT current_date()' message='JDBC driver: query has been canceled by user.'

 

This appears to hit some sort of timeout for the JDBC driver.

The other thing I can see is the stanza appears to be blank in this result. However the default Snowflake stanza in the DB connect app matches the stanza created in the Snowflake blogpost. 

Any troubleshooting help would be much appreciated. 

Labels (3)
0 Karma

thambisetty
SplunkTrust
SplunkTrust

Below link might be useful. 
https://community.splunk.com/t5/All-Apps-and-Add-ons/Cloud-Snowflake-DB-Connect-Integration/td-p/474...

————————————
If this helps, give a like below.
0 Karma

sourabg
Loves-to-Learn Everything

hello @AaronJaques @titchynz ,

I have posted solution that should resolve the error you have mentioned. Please check the following link 

Stack Overflow - Splunk DB Connect and Snowflake Integration Error

0 Karma

AaronJaques
New Member

Hi @titchynz , was wondering if you found a solution for this.  We are experiencing the exact same thing verbatim and was hoping perhaps you'd done all of the hard work 🙂 and have a solution that you could share. Thanks!

0 Karma

titchynz
New Member

Another sign something is not right - when I construct the database query as described in the Snowflake Integration blog post the resulting SQL string is completely malformed.

 

SQL string from the integration post: 

SQL String from blog post.png

SQL string results when I select the same options: 

malformed SQL string.png

I am able to construct the SQL string using the selection options, however each selection takes another 4-5min to load. 

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...