Splunk Search

splunk db connect - dbquery not accessible

a212830
Champion

Hi,

I have a Splunk6 search-head which has DB Connect installed on it. I configured some db connections as admin, and I can see them and query them succesfully. I want to give power-users the ability to see these connections and execute dbquery commands, but when they login and go to Splunk DB Connect -> Database query, the drop-down says "No database configured". Did something change in DB Connect? I have the following config in my local.meta file:

[database/PROD_DIPIT]
access = read : [ admin, power, user ], write : [ admin ]
export = system
owner = admin
version = 6.0
modtime = 1381931278.439294000

[database/ATERNITY_PROD]
access = read : [ admin, power, user ], write : [ admin ]
export = system
owner = admin
version = 6.0
modtime = 1381931267.361717000

[]
access = read : [ admin, power ], write : [ admin ]
export = none
version = 6.0
modtime = 1381928382.920638000

[commands]
access = read : [ admin, user ], write : [ admin ]
export = system

[commands/dbquery]
access = read : [ admin, power, user ], write : [ admin ]
export = system

pfernandez133
Explorer

Not sure that the original poster is still experiencing this problem, but for the benefit of other readers who might be, make sure that the role to which you are attempting to grant DB Connect access also has the dbx_capable capability. That fixed it for me.

0 Karma

MattZerfas
Communicator

Did you ever get this figured out? I am having the same issue. When I have a power user try to run the query from a dashboard it tells me that may database doesn't exist for that user even though I have given the power user all the access I can find.

0 Karma

araitz
Splunk Employee
Splunk Employee

Hard to tell from just that information. Can you please open a support case so we can get a diag file?

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...