All Apps and Add-ons

Java Bridge, DB Connect and Splunk Free

mgagliardi
Path Finder

I'm running Splunk 6.0.1 build 189883 and DB Connect 1.1.2 on Windows Server 2008 R2. I'm having a problem where the Java Bridge server status is always listed as "loading" (can't upload files, karma isn't high enough...sorry). This happens only after I "downgrade" the trial license to just Splunk Free...prior to that the Java Bridge status is properly listed as "running". If I run a check on it via command line (status.py) the output does seem to indicate that it's OK and "running".

So...how the heck do I get it to list properly in the GUI?

0 Karma

araitz
Splunk Employee
Splunk Employee

The Splunk App for DBConnect is only compatible with Splunk Enterprise, as it requires permissions, authorization, etc. It is not compatible with Splunk Free.

mgagliardi
Path Finder

That doesn't seem correct. 99% of DB Connect is working fine. I can add DB sources, query them, etc. The only thing that's not working is the Java Bridge status (it's running, which I can see if I run status.py at command line).

The last time I used Splunk was about a year ago; I used the free version with DB Connect at that time. I have a strong recollection that the Java Bridge status was working then (as was all of the DB Connect functionality).

Also, Enterprise isn't indicated as a requirement:
http://docs.splunk.com/Documentation/DBX/latest/DeployDBX/Deploymentrequirements

0 Karma

mgagliardi
Path Finder

Over in splunkd_access log I'm seeing:

"GET /services/authentication/users/admin HTTP/1.0" 402

I feed that URL into a browser I receive:




In handler 'users': Requires license feature='Auth'


It appears that the Java Bridge status view/function is trying to execute under/using auth, but that's not supported in the free version. Does anyone know how to "fix" this problem? Is there a hack I can put in place or a setting I can change to modify that view/function such that it stops trying to use auth?

0 Karma

mgagliardi
Path Finder

Further "testing" seems to indicate some kind of problem originating out of the move from a trial license to the free license. In the web_access.log I see the following when I access the DB Connect "home" page:

"GET /en-US/custom/dbx/dbx/status?nocache=1391702645347 HTTP/1.1" 500

If I feed that URL into a browserI get a 402 error:

LicenseRestriction: [HTTP 402] Current license does not allow the requested action

TBC

0 Karma

mgagliardi
Path Finder

OK...inputs are indeed working, etc. Combing the web_access.log I've found that when I request /app/dbx/dbxstatus I'm getting an HTTP 500 error. This was not happening until I changed to a Splunk Free license around noon yesterday...prior to that everything was fine. Any ideas? Other logs I should go look at or a logging level I could crank up?

Seems like the error lies somewhere inside the web page begin hit and/or the script it calls for JB health. If I run that python script in the command line I get back the output I'd expect...just not via the webpage.

0 Karma

mgagliardi
Path Finder

There are no errors in the dbx or jbridge logs and queries to the single SQL DB I have configured work perfectly. It's just the GUI not updating the status of Java Bridge. It works fine as long as the trial license is in place...only stops working after I convert to free. So what is it about the call being made (to update status) that requires something only available in the non-free edition? I'm thinking it's some kind of permissions problem.

Is there a log that might show me the presumably stalled/rejected call being made to get the status of Java Bridge?

0 Karma

lukejadamec
Super Champion

It is possible that you're having a password issue. I'm not sure how many db connections you have, but you could try opening them up and saving them with the passwords re-entered.
Are you seeing any errors in the dbx.log or jbridge.log?

0 Karma

mgagliardi
Path Finder

Yes, they are. Things do appear to be working as necessary but the GUI is misleading and will probably cause users (and me) to freak out. I'm hopeful there's just some easy fix to it.

0 Karma

lukejadamec
Super Champion

Are the inputs working?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...