Deployment Architecture

How to configure DBX Connect and Search Head Pooling in distributed configuration?

kenmcgarrahan
Explorer

Attempting to configure DBX in a distributed configuration following the guidance at:

http://docs.splunk.com/Documentation/DBX/1.1.4/DeployDBX/Setupsearchheadpooling

Attempting to execute the dbx_shpinst.py script against any DB entry yields the same error:

/apps/splunk/bin/splunk cmd python
/${shared-volume}/etc/apps/dbx/bin/dbx_shpinst.py search-head:8089 --user admin --db
my_db_name

splunk password:

database password:

No handlers could be found for logger "splunk.rest"

Could not validate password

Splunk is 6.0.1. DBX is V1.1.4.

Any guidance on resolving this error?

1 Solution

kenmcgarrahan
Explorer

Problem was ultimately traced to a firewall issue which prevented the DB connection.
Splunk support helpfully pointed out that setting 'validate' to 'False' in dbx/bin/dbx_shpinst.py allows bypassing of DB check to validate successful creation of distributed.conf.

View solution in original post

kenmcgarrahan
Explorer

Problem was ultimately traced to a firewall issue which prevented the DB connection.
Splunk support helpfully pointed out that setting 'validate' to 'False' in dbx/bin/dbx_shpinst.py allows bypassing of DB check to validate successful creation of distributed.conf.

sroback_splunk
Splunk Employee
Splunk Employee

Hi. Need more information to properly troubleshoot this - log files, etc. Might be a bug. Please file a support case on this issue for proper diagnosis at : https://www.splunk.com/index.php/submit_issue

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...