Splunk Search

DB Connect Quit Working

kmcconnell
Path Finder

All database connections quit working at the same time. I have checked the splunkd.log, dbx.log, and the jbridge.log and do not see any errors. When I restart Splunk I see in the dbx.log where it loads all the monitors and executes them, but then nothing shows up after that except the following two lines every few minutes. Any ideas would be MUCH appreciated!!

2014-01-31 19:31:00.740 dbx3877:INFO:Splunkd - Splunkd REST Keep-alive successful for user admin
2014-01-31 19:31:00.740 dbx3877:INFO:ExecutionContext - Execution finished in duration=0 ms

Tags (1)
0 Karma
1 Solution

lukejadamec
Super Champion

Is the java bridge server running? If not, open taskmgr and stop the service. It sounds like java is hung, and I've seen this before where not even a reboot of the computer would fix the problem, but a manual kill of the java process would.

View solution in original post

lukejadamec
Super Champion

Is the java bridge server running? If not, open taskmgr and stop the service. It sounds like java is hung, and I've seen this before where not even a reboot of the computer would fix the problem, but a manual kill of the java process would.

linu1988
Champion

it was a issue with older dbx, upgrade to the latest version if not done.

0 Karma

reed_kelly
Contributor

Also, did you try the TDS driver. It can do Integrated Security as well and may be better written.

0 Karma

reed_kelly
Contributor

Could it have been a java memory problem? What did you have for -Xmx in the java bridge options?

0 Karma

kmcconnell
Path Finder

lukejadamec put me on right track (if was a Java issue). I had to kill the java process being run by Splunk. After I restarted, DB connected worked correctly. Thanks!

0 Karma

lukejadamec
Super Champion

One other thing, you have to be running a query in DB Connect when you kill java. Java will automatically restart, and the query should error out with a code 47, but when you run the query again it should work.

0 Karma

kmcconnell
Path Finder

All the connections are Microsoft SQL Server. On the “External Databases”, when I try to re-save the connection I get the following error at the top of the page.

“Encountered the following error while trying to update: Splunkd daemon is not responding: (‘The read operation timed out’)

If I take one of the existing queries and modify it to only return a few rows, it just sits there and never returns anything.

0 Karma

lukejadamec
Super Champion

Can you query the databases from DB Connect > Query?
Can you open and save the DB Connect > Database Inputs without error?

0 Karma

linu1988
Champion

Did you check the account which you are using if locked or not? Which database connection are you using? Try running some queries it will throw some exceptions, figure out what may cause the issue.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...