Splunk Search

Can't connect to SQLite database

responsys_cm
Builder

I'm using the DB Connect V1 app in Splunk 6.2 on an Ubuntu Linux server. I have a local sqlite database. I can use the sqlite3 command to connect to it successfully.

I've created a database connection that looks like:

[vFeed]

database = /opt/vFeed/vfeed.db
host = localhost

isolation_level = DATABASE_SETTING

type = sqlite

disabled = 0
username = root

When I try and browse the schema, I get the following error:

The internal search "| dbinfo database="vFeed" type=schemas | sort -default | eval label=if(isnull(default),schema,schema+" (default)")" for the "Splunk.Module.SearchSelectLister" module failed.

I'm not seeing any error messages.

What am I doing wrong here?

Thx.

Craig

Tags (1)
0 Karma

responsys_cm
Builder

The database file is vfeed.db. Renaming it vfeed.sqlite and placing it in the /opt/splunk/var/dbx folder solved the problem.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...