<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What does this search head cluster function alert WARN messages mean? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/What-does-this-search-head-cluster-function-alert-WARN-messages/m-p/447857#M15741</link>
    <description>&lt;P&gt;That's just a wild guess: Are you using Enterprise Security? And on Windows?&lt;/P&gt;

&lt;P&gt;Skalli&lt;/P&gt;</description>
    <pubDate>Wed, 26 Jun 2019 09:03:48 GMT</pubDate>
    <dc:creator>skalliger</dc:creator>
    <dc:date>2019-06-26T09:03:48Z</dc:date>
    <item>
      <title>What does this search head cluster function alert WARN messages mean?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-does-this-search-head-cluster-function-alert-WARN-messages/m-p/447853#M15737</link>
      <description>&lt;P&gt;Every other day, we are getting following error on the internal index. Nearly 65,000 messages are generated for less than 15mins. What does this error actually mean?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;_WARN  SHCFunctions - alert csv wrong action  csv = key,expire,ACTION,MD5,"__mv_key","__mv_expire","__mv_ACTION","__mv_MD5"\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n"","","","",,,,\n_
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 24 Jun 2019 21:42:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-does-this-search-head-cluster-function-alert-WARN-messages/m-p/447853#M15737</guid>
      <dc:creator>spectrum2035</dc:creator>
      <dc:date>2019-06-24T21:42:43Z</dc:date>
    </item>
    <item>
      <title>Re: What does this search head cluster function alert WARN messages mean?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-does-this-search-head-cluster-function-alert-WARN-messages/m-p/447854#M15738</link>
      <description>&lt;P&gt;I've never seen that logging category and I don't see &lt;CODE&gt;SHCFunctions&lt;/CODE&gt; in the &lt;CODE&gt;log.cfg&lt;/CODE&gt; either. Is that some custom app that logs into your _internal index?&lt;/P&gt;

&lt;P&gt;Skalli&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2019 19:01:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-does-this-search-head-cluster-function-alert-WARN-messages/m-p/447854#M15738</guid>
      <dc:creator>skalliger</dc:creator>
      <dc:date>2019-06-25T19:01:31Z</dc:date>
    </item>
    <item>
      <title>Re: What does this search head cluster function alert WARN messages mean?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-does-this-search-head-cluster-function-alert-WARN-messages/m-p/447855#M15739</link>
      <description>&lt;P&gt;@spectrum2035&lt;BR /&gt;
Only the error does not give much info. Can you try to add some more info about the error ?&lt;BR /&gt;
I am guessing if SHC means Search Head Cluster. Please check if you are able to find any errors/warnings in Monitoring Console on your search head dashboards and any warnings on General Health checks&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2019 20:20:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-does-this-search-head-cluster-function-alert-WARN-messages/m-p/447855#M15739</guid>
      <dc:creator>amitm05</dc:creator>
      <dc:date>2019-06-25T20:20:24Z</dc:date>
    </item>
    <item>
      <title>Re: What does this search head cluster function alert WARN messages mean?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-does-this-search-head-cluster-function-alert-WARN-messages/m-p/447856#M15740</link>
      <description>&lt;P&gt;I did check the general health status of the SHC in DMC and couldnt find anything alarming...&lt;/P&gt;

&lt;P&gt;Following are the 4 logs which was indexed just before the event happened....&lt;/P&gt;

&lt;P&gt;I ACCESS   [conn47] Successfully authenticated as principal __system on local&lt;BR /&gt;
I NETWORK  [thread1] connection accepted from 10.10.10.3:50374 #47 (23 connections now open)&lt;BR /&gt;
127.0.0.1 - splunk-system-user [25/Jun/2019:16:16:04.090 +0100] "GET /services/data/inputs/threatlist?output_mode=json&amp;amp;search=disabled%3D%22false%22 HTTP/1.0" 200 41063 - - - 92ms&lt;BR /&gt;
I ACCESS   [conn20] Successfully authenticated as principal __system on local&lt;/P&gt;

&lt;P&gt;If I look back to the earlier one's i have license  usage events OR StatusMgr related events.. so there is no specific pattern..&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:03:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-does-this-search-head-cluster-function-alert-WARN-messages/m-p/447856#M15740</guid>
      <dc:creator>spectrum2035</dc:creator>
      <dc:date>2020-09-30T01:03:21Z</dc:date>
    </item>
    <item>
      <title>Re: What does this search head cluster function alert WARN messages mean?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-does-this-search-head-cluster-function-alert-WARN-messages/m-p/447857#M15741</link>
      <description>&lt;P&gt;That's just a wild guess: Are you using Enterprise Security? And on Windows?&lt;/P&gt;

&lt;P&gt;Skalli&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2019 09:03:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-does-this-search-head-cluster-function-alert-WARN-messages/m-p/447857#M15741</guid>
      <dc:creator>skalliger</dc:creator>
      <dc:date>2019-06-26T09:03:48Z</dc:date>
    </item>
    <item>
      <title>Re: What does this search head cluster function alert WARN messages mean?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-does-this-search-head-cluster-function-alert-WARN-messages/m-p/447858#M15742</link>
      <description>&lt;P&gt;Yes we are using ES but on RHEL&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2019 22:41:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-does-this-search-head-cluster-function-alert-WARN-messages/m-p/447858#M15742</guid>
      <dc:creator>spectrum2035</dc:creator>
      <dc:date>2019-06-26T22:41:03Z</dc:date>
    </item>
    <item>
      <title>Re: What does this search head cluster function alert WARN messages mean?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-does-this-search-head-cluster-function-alert-WARN-messages/m-p/447859#M15743</link>
      <description>&lt;P&gt;check ES version and Splunk version compatibility:&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/VersionCompatibility/current/Matrix/CompatMatrix"&gt;https://docs.splunk.com/Documentation/VersionCompatibility/current/Matrix/CompatMatrix&lt;/A&gt;&lt;BR /&gt;
contact splunk support too&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2019 02:48:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-does-this-search-head-cluster-function-alert-WARN-messages/m-p/447859#M15743</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2019-06-27T02:48:59Z</dc:date>
    </item>
    <item>
      <title>Re: What does this search head cluster function alert WARN messages mean?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-does-this-search-head-cluster-function-alert-WARN-messages/m-p/447860#M15744</link>
      <description>&lt;P&gt;Thanks adonio, we have upgraded our servers nearly a year back and this started showing up for last 1 month only.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2019 07:52:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-does-this-search-head-cluster-function-alert-WARN-messages/m-p/447860#M15744</guid>
      <dc:creator>spectrum2035</dc:creator>
      <dc:date>2019-06-27T07:52:22Z</dc:date>
    </item>
    <item>
      <title>Re: What does this search head cluster function alert WARN messages mean?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-does-this-search-head-cluster-function-alert-WARN-messages/m-p/447861#M15745</link>
      <description>&lt;P&gt;Hi @spectrum2035,&lt;/P&gt;

&lt;P&gt;Do you still have this issue ? Seems like a misconfigured lookup or alert action to generate a csv. can you try to link this to any newly added alert action ?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2019 08:25:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-does-this-search-head-cluster-function-alert-WARN-messages/m-p/447861#M15745</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-06-27T08:25:08Z</dc:date>
    </item>
    <item>
      <title>Re: What does this search head cluster function alert WARN messages mean?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/What-does-this-search-head-cluster-function-alert-WARN-messages/m-p/447862#M15746</link>
      <description>&lt;P&gt;facing same problem ... no clues .... doesn't look like there is a correlation to errors reported by other splunkd logging components. just sudden spikes of SHCFunctions warnings.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2019 14:03:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/What-does-this-search-head-cluster-function-alert-WARN-messages/m-p/447862#M15746</guid>
      <dc:creator>smitra_splunk</dc:creator>
      <dc:date>2019-08-13T14:03:25Z</dc:date>
    </item>
  </channel>
</rss>

