Security

Splunk DB connect - Intermittent errors with oracle driver

venkatasajja
New Member

We are seeing couple of splunk db connect errors intermittently. We are using a latest version of DB connect (1.1.3 ) in our splunk 5.0.6

  1. We have configured an external Database connection through Splunk DB connect.
  2. Through DB info within the Splunk DB connect, we are also able to look for schemas etc indicating a successful connection to the database.
  3. we have scheduled couple of searches in Splunk that queries this database and fetches the events into a Summary index.
  4. And we noticed that some of the search runs are giving one of the below errors intermittently.

2014-02-28 10:25:04.972 dbx7653:ERROR:DatabaseQueryCommand - Error while executing command: Database xxxxx does not exist! ( This database exists on search heads config file as well. Not sure if this needs to be configured on Indexers as well ? ). In one run, it complains about this error and in next run, it runs successfully indexing the events

2014-02-28 11:00:53.843 dbx8200:ERROR:DatabaseQueryCommand - Error while executing command: Error getting database connection: ORA-28000: the account is locked. ( We are looking at the database end. But since this is intermittent, we would also like to check with Splunk support for any possible bugs )

0 Karma

araitz
Splunk Employee
Splunk Employee

Tough to tell, but my guess is that this is on the Oracle DB side. It seems that ORA-28000 has given others fits in the past:

http://stackoverflow.com/questions/13230462/ora-28000-account-is-locked-error-in-qtp

https://community.oracle.com/thread/2470425?tstart=0

My best guess is that something else, a script or command, is using the wrong password for this account and is intermittently locking it.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...