Splunk Search

DBX Query

JacketPotato
New Member

Hi,

I am having issues with dbx queries

I created a dashboard with dbx queries, I can run the queries, dashboard displays fine for me and other admins but standard users (non admins) get "unknown search command 'dbxquery'".

I am domain admin.
I am an admin on splunk

The users having the issue

  • Are not domain admin
  • They have permission on the sql database that splunk queries

I was looking at the article that would kind of explain why it works for me (being local admin on the splunk server)
https://docs.splunk.com/Documentation/DBX/3.3.1/DeployDBX/Configuresecurityandaccesscontrols

Before using DB Connect, the logged-in user must have the ability to write to the $SPLUNK_HOME/var directory (%SPLUNK_HOME%\var on Windows hosts) and to $SPLUNK_HOME/etc/apps/splunk_app_db_connect ($SPLUNK_HOME/etc/apps/splunk_app_db_connect on Windows hosts) and its sub-directories

Am i reading this right? i have to grant read access on the splunk server directly if the dashboard user doesn't have permission to these folders? Surely i have that wrong? It can't be the case?

Thanks.

0 Karma

vgtk4431
Path Finder

the users needs to have access to the custom commands "dbxquery"

settings > advanced search > search commands

 

you have to tweak the permissions on the command. By default, only users with the role "admin & db_connect_*" have access to the command.

Either you expand the right, or you add the user that needs to do dbxquery the role "db_connect_user"

0 Karma

JacketPotato
New Member

Thanks I'll have a look.
So the article i refer to is not relevant?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...