|
Good morning, I am suddenly receiving this error and not able to index:
The other day I received this error:
I have recently upgraded from 4.1.3 to 4.1.5. There was no immediate change but I did start using FSChange to monitor some directories. I removed FSChange stanzas that I added from the inputs.conf and restarted and I am still having the issue, though the warning moved back to the second error. In splunkd.log I see:
I am not sure if it is related. Perhaps with all my alerts that run at various intervals (10 min, 15 min, 20 min, 30 min) I am eclipsing 8. Would that cause the errors regarding not indexing? I am currently not able to view any data for the last two days. Thanks for any help! Kevin |
|
For a "down" kind of scenario like this, it may be best to contact splunk support. Email them with a link to this page, run the " Things I would check:
I have an open case and am working with them. Disk space is fine, I disabled a scheduled saved search, but just the one I added prior to this problem occurring. I am looking into #2. Thanks very much for all your help.
(15 Oct '10, 15:50)
kholleran
Unfortunately, those did not work and I have not heard back in a couple days regarding my case with Splunk. Any other thoughts as I am completely down. If this goes on much longer I may have to downgrade back to 4.1.3, even if that means ripping out and re-setting up the installation. Thanks.
(19 Oct '10, 13:36)
kholleran
1
I suggest calling splunk support. Copied from the "Contact Us" web page: If you have purchased Enterprise Support, please call the Enterprise Support line at +1 415.848.8400 option 3.
(20 Oct '10, 14:44)
Lowell ♦
|

What did it end up being?