<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Message &amp;quot;Streamed search execute failed because: Error in 'lookup' command: Failed to re-open lookup file&amp;quot; after upgrade in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Message-quot-Streamed-search-execute-failed-because-Error-in/m-p/569975#M10262</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/194646"&gt;@lukasmecir&lt;/a&gt;, I think you should raise a support case for this issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In fixed issues for Splunk 8.1.2, I found this promising note.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;2021-01-29 SPL-198149, SPL-199358 KVStore lookup indexing leads to slow search performance and intermittent errors in searches.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;See here&amp;nbsp;&lt;SPAN&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.2/ReleaseNotes/Fixedissues#Highlighted_issues" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.2/ReleaseNotes/Fixedissues#Highlighted_issues&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;but in 8.2.2&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;EM&gt;2021-05-21 SPL-206067 With large KVstore temporal lookups that are replicated to indexers, turning ON enable_splunkd_kv_lookup_indexing may lead to indexer crash&lt;/EM&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.2/ReleaseNotes/KnownIssues#Distributed_search_and_search_head_clustering_issues" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.2/ReleaseNotes/KnownIssues#Distributed_search_and_search_head_clustering_issues&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So please raise a support case and get the SME's view on how best to address this.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Cheers&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 07 Oct 2021 03:43:10 GMT</pubDate>
    <dc:creator>jamesmurphy_spl</dc:creator>
    <dc:date>2021-10-07T03:43:10Z</dc:date>
    <item>
      <title>Message "Streamed search execute failed because: Error in 'lookup' command: Failed to re-open lookup file" after upgrade</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Message-quot-Streamed-search-execute-failed-because-Error-in/m-p/569878#M10251</link>
      <description>&lt;P&gt;Hi, I would like to ask for help with following problem:&lt;BR /&gt;We have SH cluster (3 nodes) and IDX cluster (3 nodes). We upgraded it from 8.0.9 to 8.1.6 because of EOS of 8.0 version. Everything looks fine, except one thing - sometimes this happens:&lt;BR /&gt;I run a search. The search starts, but after a while it stucks (on the line below the place for entering the SPL query, the number of events stops) and after cca 5 minutes the search ends with an error message "Streamed search execute failed because: Error in 'lookup' command: Failed to re-open lookup file: '/srv/app/int/secmon/splunk/var/run/searchpeers/08270BDA-BE03-4A78-8C6C-95A9CE10BB8D-1633508003/kvstore_s_SA-IdeRjww0FotymhlCIaS1cqkc05a_assetsXy0Y9f6F5lMW4rOy8KLC@P22'"&lt;BR /&gt;It happens completely randomly, does not matter what data I search for.&lt;BR /&gt;Sometimes this message is generated by only 1 IDX node, sometimes by 2, sometimes by all 3 nodes in IDX cluster.&lt;BR /&gt;Error message is always exactly the same (except the part "1633508003", which is time of search).&lt;BR /&gt;Sometimes I get partial results (some events returned), sometimes not (0 events returned).&lt;BR /&gt;Before upgrade there was no message like this. Could someone help with this? Is it related to the upgrade? And how to fix it? I tried to search through Splunk Community, google around, but did not find anything useful... Thanks in advance.&lt;/P&gt;&lt;P&gt;Lukas Mecir&lt;/P&gt;</description>
      <pubDate>Wed, 06 Oct 2021 13:04:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Message-quot-Streamed-search-execute-failed-because-Error-in/m-p/569878#M10251</guid>
      <dc:creator>lukasmecir</dc:creator>
      <dc:date>2021-10-06T13:04:29Z</dc:date>
    </item>
    <item>
      <title>Message "Streamed search execute failed because: Error in 'lookup' command: Failed to re-open lookup file" after upgrade</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Message-quot-Streamed-search-execute-failed-because-Error-in/m-p/569975#M10262</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/194646"&gt;@lukasmecir&lt;/a&gt;, I think you should raise a support case for this issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In fixed issues for Splunk 8.1.2, I found this promising note.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;2021-01-29 SPL-198149, SPL-199358 KVStore lookup indexing leads to slow search performance and intermittent errors in searches.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;See here&amp;nbsp;&lt;SPAN&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.2/ReleaseNotes/Fixedissues#Highlighted_issues" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.2/ReleaseNotes/Fixedissues#Highlighted_issues&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;but in 8.2.2&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;EM&gt;2021-05-21 SPL-206067 With large KVstore temporal lookups that are replicated to indexers, turning ON enable_splunkd_kv_lookup_indexing may lead to indexer crash&lt;/EM&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.2/ReleaseNotes/KnownIssues#Distributed_search_and_search_head_clustering_issues" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.2/ReleaseNotes/KnownIssues#Distributed_search_and_search_head_clustering_issues&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So please raise a support case and get the SME's view on how best to address this.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Cheers&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Oct 2021 03:43:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Message-quot-Streamed-search-execute-failed-because-Error-in/m-p/569975#M10262</guid>
      <dc:creator>jamesmurphy_spl</dc:creator>
      <dc:date>2021-10-07T03:43:10Z</dc:date>
    </item>
    <item>
      <title>Re: Message "Streamed search execute failed because: Error in 'lookup' command: Failed to re-open lookup file"</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Message-quot-Streamed-search-execute-failed-because-Error-in/m-p/569996#M10263</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/31672"&gt;@jamesmurphy_spl&lt;/a&gt;&amp;nbsp;, thanks for reply. I found the same info you mention in Splunk 8.1.2 fixed issues and it attracted me too. &lt;EM&gt;SPL-206067&lt;/EM&gt; probably is not the reason, because&amp;nbsp;&lt;EM&gt;enable_splunkd_kv_lookup_indexing &lt;/EM&gt;is set to&lt;EM&gt; false &lt;/EM&gt;in our&amp;nbsp; searchpeers.&lt;/P&gt;&lt;P&gt;Anyway, I raised support case and we'll see...&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Thu, 07 Oct 2021 07:43:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Message-quot-Streamed-search-execute-failed-because-Error-in/m-p/569996#M10263</guid>
      <dc:creator>lukasmecir</dc:creator>
      <dc:date>2021-10-07T07:43:49Z</dc:date>
    </item>
    <item>
      <title>Re: Message "Streamed search execute failed because: Error in 'lookup' command: Failed to re-open lookup file"</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Message-quot-Streamed-search-execute-failed-because-Error-in/m-p/570054#M10277</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/194646"&gt;@lukasmecir&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was referring to setting the value to true in the limits.conf file. See detail&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;KVStore lookup indexing leads to slow search performance and intermittent errors in searches.

In Splunk Enterprise version 8.1.2, if you encounter this problem change the enable_splunkd_kv_lookup_indexing parameter to true in the [lookup] stanza of limits.conf in your $SPLUNK_HOME/etc/system/local directory on your search peers.&lt;/LI-CODE&gt;&lt;P&gt;but it's perfectly good that you've raised a support case. Fingers crossed you get resolution my friend.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best&amp;nbsp;&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;</description>
      <pubDate>Thu, 07 Oct 2021 12:37:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Message-quot-Streamed-search-execute-failed-because-Error-in/m-p/570054#M10277</guid>
      <dc:creator>jamesmurphy_spl</dc:creator>
      <dc:date>2021-10-07T12:37:55Z</dc:date>
    </item>
    <item>
      <title>Re: Message "Streamed search execute failed because: Error in 'lookup' command: Failed to re-open lookup file"</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Message-quot-Streamed-search-execute-failed-because-Error-in/m-p/571634#M10410</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/194646"&gt;@lukasmecir&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you already got a answer from splunk support? How could you fix this issue?&lt;/P&gt;&lt;P&gt;Thanks and regards&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2021 07:57:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Message-quot-Streamed-search-execute-failed-because-Error-in/m-p/571634#M10410</guid>
      <dc:creator>urbach</dc:creator>
      <dc:date>2021-10-21T07:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: Message "Streamed search execute failed because: Error in 'lookup' command: Failed to re-open lookup file"</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Message-quot-Streamed-search-execute-failed-because-Error-in/m-p/621967#M14603</link>
      <description>&lt;P&gt;Please try increasing&amp;nbsp;&lt;SPAN&gt;max_memtable_bytes in limits.conf to higher than default i.e., 25 MB to at least 50MB or more.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Nov 2022 09:29:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Message-quot-Streamed-search-execute-failed-because-Error-in/m-p/621967#M14603</guid>
      <dc:creator>amaithani</dc:creator>
      <dc:date>2022-11-24T09:29:49Z</dc:date>
    </item>
  </channel>
</rss>

