All Apps and Add-ons

Where can I look to find out why an Oracle dbconnect is failing?

shazam99337
New Member

I have verified the connection is sound, and when I go through the GUI creating/editing the input, it pulls data. But nothing is coming into the indexer and there appears to be an error. So, where do I find out what the actual error is?.

2018-02-28 15:30:47.058 -0800 INFO c.s.dbx.server.task.listeners.JobMetricsListener - action=collect_job_metrics connection=MYDATABASEReport jdbc_url=null record_read_success_count=674 db_read_time=47048 record_read_error_count=1 hec_record_process_time=8 format_hec_success_count=674 status=FAILED input_name=MYDATABASEReport batch_size=1000 error_threshold=N/A is_jmx_monitoring=false start_time=2018-02-28_03:30:00 end_time=2018-02-28_03:30:47 duration=47057 read_count=2696 write_count=0 filtered_count=0 error_count=0

I've used two other methods to get this data, both through TOAD (our oracle UI) and a home-grown data extract tool on a remote server.

Any help would be appreciated.

Thanks.

0 Karma

shazam99337
New Member

So...in this particular case the part

record_read_success_count=674

was indicative of an error at row 675. I fixed that. Now I am getting this:

2018-03-01 14:51:12.868 -0800 INFO c.s.dbx.server.task.listeners.JobMetricsListener - action=collect_job_metrics connection=MYDATABASEReport jdbc_url=null status=FAILED input_name=MYDATABASEReport batch_size=1000 error_threshold=N/A is_jmx_monitoring=false start_time=2018-03-01_02:50:00 end_time=2018-03-01_02:51:12 duration=72866 read_count=6066 write_count=0 filtered_count=0 error_count=0

I thought maybe there would be an issue with record number 6067 but its nearly identical to the 6066 implied in the message.

Anyone know where I can find splunk's reason for failure?

0 Karma

alemarzu
Motivator

Hi there mate, any update on this? I'm struggling with something very similar to this.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...