Security

Splunk DB connect - Intermittent errors with oracle driver

venkatasajja
New Member

We are seeing couple of splunk db connect errors intermittently. We are using a latest version of DB connect (1.1.3 ) in our splunk 5.0.6

  1. We have configured an external Database connection through Splunk DB connect.
  2. Through DB info within the Splunk DB connect, we are also able to look for schemas etc indicating a successful connection to the database.
  3. we have scheduled couple of searches in Splunk that queries this database and fetches the events into a Summary index.
  4. And we noticed that some of the search runs are giving one of the below errors intermittently.

2014-02-28 10:25:04.972 dbx7653:ERROR:DatabaseQueryCommand - Error while executing command: Database xxxxx does not exist! ( This database exists on search heads config file as well. Not sure if this needs to be configured on Indexers as well ? ). In one run, it complains about this error and in next run, it runs successfully indexing the events

2014-02-28 11:00:53.843 dbx8200:ERROR:DatabaseQueryCommand - Error while executing command: Error getting database connection: ORA-28000: the account is locked. ( We are looking at the database end. But since this is intermittent, we would also like to check with Splunk support for any possible bugs )

0 Karma

araitz
Splunk Employee
Splunk Employee

Tough to tell, but my guess is that this is on the Oracle DB side. It seems that ORA-28000 has given others fits in the past:

http://stackoverflow.com/questions/13230462/ora-28000-account-is-locked-error-in-qtp

https://community.oracle.com/thread/2470425?tstart=0

My best guess is that something else, a script or command, is using the wrong password for this account and is intermittently locking it.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...