Getting Data In

Splunk DB connect - Cannot get schemas

xlin
Engager

Hello splunk community,

There might be some configuration issues in our environment, but I could not find anything standing out even after I turned on all logging to "DEBUG" mode. Following are the symptoms of the issue:

1. On the "New Input" left manual:

I am able to pick a connection; a Catalog ("TE"), but then "Schema" section turns red and shows "Cannot get schemas". < the user has full admin right on the server>

2. On the "SQLEditor":

If I type in SELECT * from TE.dbo.Node, and execute the query, the correct results will be returned.

So it seems that on the same splunk page, the results are contradicting each other, can anyone help to point me to the right direction on how to resolve this.

The DB connect version is 3.2.0; and I am using connection type MS-SQL Server Generic Driver (Ver. 3.0), SQL server itself is SQL2016.

Also, please also note that the same connection and user setup is able to get the other schemas on the same SQL instance without any issues; only failed in one particular database, and even after I tried to restore the troublesome db to a different name.

Thank you very much in advance.

Labels (1)
0 Karma

nsanzar_splunk
Splunk Employee
Splunk Employee

As per harsmarvania57:

In DB, there are schemas available and each schema have different table. So in DB you need to provide schema access & table access to user from which splunk is trying to fetch data.

Original post:  https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-DB-Connect-Why-am-I-getting-error-quot-n... 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Maximizing the Value of Splunk ES 8.x

Splunk Enterprise Security (ES) continues to be a leader in the Gartner Magic Quadrant, reflecting its pivotal ...