<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why are we are receiving error &amp;quot;-0500 ERROR DataModelEvaluator - Data model 'Security_DSB' was not found&amp;quot; search head instances? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-we-are-receiving-error-quot-0500-ERROR/m-p/240429#M9018</link>
    <description>&lt;P&gt;Found this here on  &lt;A href="https://answers.splunk.com/answers/272912/after-i-created-a-dashboard-as-one-user-and-shared.html"&gt;Answers&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 07 May 2018 13:03:12 GMT</pubDate>
    <dc:creator>sves</dc:creator>
    <dc:date>2018-05-07T13:03:12Z</dc:date>
    <item>
      <title>Why are we are receiving error "-0500 ERROR DataModelEvaluator - Data model 'Security_DSB' was not found" search head instances?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-we-are-receiving-error-quot-0500-ERROR/m-p/240426#M9015</link>
      <description>&lt;P&gt;Hi All, &lt;/P&gt;

&lt;P&gt;We are getting this error in Splunk search head instances &lt;CODE&gt;-0500 ERROR DataModelEvaluator - Data model 'Security_DSB' was not found.&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;We are getting the above error message in splunkd.log, not sure what as went wrong really and why we are getting this error message in splunkd.log after restarting the Splunk services. Kindly guide us in fixing this issue.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;0500 ERROR DataModelEvaluator - Data model 'Security_DSB' was not found.
0500 ERROR DataModelEvaluator - Data model 'Security_DSB' was not found.
0500 ERROR DataModelEvaluator - Data model 'Security_DSB' was not found.
0500 ERROR DataModelEvaluator - Data model 'Security_DSB' was not found.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;thanks in advance. &lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2017 17:07:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-we-are-receiving-error-quot-0500-ERROR/m-p/240426#M9015</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-01-17T17:07:24Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we are receiving error "-0500 ERROR DataModelEvaluator - Data model 'Security_DSB' was not found" search head instances?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-we-are-receiving-error-quot-0500-ERROR/m-p/240427#M9016</link>
      <description>&lt;P&gt;Hi All, Can anyone throw me some lights on this error .&lt;/P&gt;

&lt;P&gt;thanks in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2017 10:39:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-we-are-receiving-error-quot-0500-ERROR/m-p/240427#M9016</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2017-02-06T10:39:45Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we are receiving error "-0500 ERROR DataModelEvaluator - Data model 'Security_DSB' was not found" search head instances?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-we-are-receiving-error-quot-0500-ERROR/m-p/240428#M9017</link>
      <description>&lt;P&gt;For now, all the light I can shed is that I see athe exact same error (different data model though) with one of my Splunk customers. The "-0500" in the beginning of your line is your time zone, so not really a part of the message. I will post my findings if I figure out what is going on with this error message.&lt;/P&gt;</description>
      <pubDate>Mon, 07 May 2018 12:51:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-we-are-receiving-error-quot-0500-ERROR/m-p/240428#M9017</guid>
      <dc:creator>sves</dc:creator>
      <dc:date>2018-05-07T12:51:43Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we are receiving error "-0500 ERROR DataModelEvaluator - Data model 'Security_DSB' was not found" search head instances?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-we-are-receiving-error-quot-0500-ERROR/m-p/240429#M9018</link>
      <description>&lt;P&gt;Found this here on  &lt;A href="https://answers.splunk.com/answers/272912/after-i-created-a-dashboard-as-one-user-and-shared.html"&gt;Answers&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 May 2018 13:03:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-we-are-receiving-error-quot-0500-ERROR/m-p/240429#M9018</guid>
      <dc:creator>sves</dc:creator>
      <dc:date>2018-05-07T13:03:12Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we are receiving error "-0500 ERROR DataModelEvaluator - Data model 'Security_DSB' was not found" search head instances?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-we-are-receiving-error-quot-0500-ERROR/m-p/240430#M9019</link>
      <description>&lt;P&gt;thanks sves for you are update. &lt;/P&gt;</description>
      <pubDate>Mon, 07 May 2018 13:56:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-we-are-receiving-error-quot-0500-ERROR/m-p/240430#M9019</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2018-05-07T13:56:47Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we are receiving error "-0500 ERROR DataModelEvaluator - Data model 'Security_DSB' was not found" search head instances?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-we-are-receiving-error-quot-0500-ERROR/m-p/240431#M9020</link>
      <description>&lt;P&gt;In the case of my customer, the data model json file was missing, and the datamodels.conf was set up with acceleration = 1. So every 5 minutes, Splunk would be complaining. Simply removing references to the missing data model is an easy fix. Or, recreate the data model from backup if one is available. &lt;/P&gt;

&lt;P&gt;I see in other cases this has to do with permission - check out &lt;A href="https://answers.splunk.com/answers/272912/after-i-created-a-dashboard-as-one-user-and-shared.html"&gt;this answers article&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 May 2018 14:11:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-we-are-receiving-error-quot-0500-ERROR/m-p/240431#M9020</guid>
      <dc:creator>sves</dc:creator>
      <dc:date>2018-05-07T14:11:03Z</dc:date>
    </item>
  </channel>
</rss>

