Logged along with each SQL query is the user that ran the query, the parameters, the number of results returned, and the name of the input, output, or lookup that Splunk ran. For more information about what Splunk Enterprise logs about itself, see " What Splunk logs about itself" in the Splunk Enterprise Troubleshooting Manual.īy default, DB Connect logs all executed SQL queries at INFO level. Database and Splunk Enterprise administrators work together to determine the optimal logging setup for their environment and decide how to handle special scenarios like troubleshooting. For example, by default non administrators can't access _internal. You can control access to logged events by limiting access to the _internal index using Splunk Enterprise roles. To view DB Connect logging activity, use a search command such as the following: splunk_app_db_connect_audit_command.*.log.splunk_app_db_connect_health_metrics.log.splunk_app_db_connect_server_access.log.The relevant log files for DB Connect are Splunk logs DB Connect activity to files in $SPLUNK_HOME/var/log/splunk and automatically indexed to _internal. Before contacting Splunk support, you might want to enable debug logging, in case you need to provide Splunk support with DB Connect debug logs. Splunk DB Connect has extensive logging options, which you can configure in Settings. If none of the roles you assign a user to has permission to either search _internal or view data with sourcetype="dbx_health", the dashboard displays the "Permission denied" error. If the health dashboard displays a "Permission denied" error message instead of any data, the problem is likely a permissions issue with the logged-on user.Ī logged-on user must have an assigned role that has access to both the _internal index and "dbx_health" source type in order to see the health dashboard. Health dashboard shows "Permission denied" error message You can also see whether DB Connect is generating any internal errors, using a search with the following parameters: For more information about the health dashboard, see Monitor database connection health. The health dashboard is a pre-configured dashboard that let's you monitor and troubleshoot several aspects of your database connections from inside Splunk Enterprise. When you're trying to figure out the cause of degraded performance or figure out how failure rates correspond to transaction type or database user, the place to start is the health dashboard in Splunk DB Connect. Have questions? In addition to these troubleshooting tips, go to Questions related to Splunk DB Connect on Splunk Answers to see what questions and answers the Splunk community has about using Splunk DB Connect. If the Troubleshooting Tool for DB Connect does not solve your issue, try the following steps. Troubleshoot common Splunk DB Connect issues using the Troubleshooting Tool for DB Connect.
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |