Security

Splunk DB connect - Intermittent errors with oracle driver

venkatasajja
New Member

We are seeing couple of splunk db connect errors intermittently. We are using a latest version of DB connect (1.1.3 ) in our splunk 5.0.6

  1. We have configured an external Database connection through Splunk DB connect.
  2. Through DB info within the Splunk DB connect, we are also able to look for schemas etc indicating a successful connection to the database.
  3. we have scheduled couple of searches in Splunk that queries this database and fetches the events into a Summary index.
  4. And we noticed that some of the search runs are giving one of the below errors intermittently.

2014-02-28 10:25:04.972 dbx7653:ERROR:DatabaseQueryCommand - Error while executing command: Database xxxxx does not exist! ( This database exists on search heads config file as well. Not sure if this needs to be configured on Indexers as well ? ). In one run, it complains about this error and in next run, it runs successfully indexing the events

2014-02-28 11:00:53.843 dbx8200:ERROR:DatabaseQueryCommand - Error while executing command: Error getting database connection: ORA-28000: the account is locked. ( We are looking at the database end. But since this is intermittent, we would also like to check with Splunk support for any possible bugs )

0 Karma

araitz
Splunk Employee
Splunk Employee

Tough to tell, but my guess is that this is on the Oracle DB side. It seems that ORA-28000 has given others fits in the past:

http://stackoverflow.com/questions/13230462/ora-28000-account-is-locked-error-in-qtp

https://community.oracle.com/thread/2470425?tstart=0

My best guess is that something else, a script or command, is using the wrong password for this account and is intermittently locking it.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...