<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Error invoking commnad: hadoop com.splunk.mr.SplunkMR - Return code: 255 in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409279#M7082</link>
    <description>&lt;P&gt;When I do a search for com.splunk.mr.SplunkMR on my linux system, it finds nothing.  Perhaps it is missing this but Im unsure how that would be missing I figure it came with the Splunk install&lt;/P&gt;</description>
    <pubDate>Thu, 24 May 2018 15:54:16 GMT</pubDate>
    <dc:creator>EricLloyd79</dc:creator>
    <dc:date>2018-05-24T15:54:16Z</dc:date>
    <item>
      <title>Error invoking commnad: hadoop com.splunk.mr.SplunkMR - Return code: 255</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409275#M7078</link>
      <description>&lt;P&gt;We have the MapR filesystem and Hunk on the same node, have set up a Provider and Virtual and Im getting an error when trying to run a query other than a basic index search.&lt;/P&gt;

&lt;P&gt;"index=test"   produces correct results&lt;BR /&gt;
"index=test keyword" produces the error below&lt;/P&gt;

&lt;P&gt;Also see screenshot attachments of Provider and VI config.&lt;/P&gt;

&lt;P&gt;Error from search.log:&lt;/P&gt;

&lt;P&gt;05-23-2018 20:49:13.581 ERROR ERP.maproly -  Caused by: java.lang.RuntimeException: summary_id did not exist in search info: {_tz=### SERIALIZED TIMEZONE FORMAT 1.0;C0;Y0 NW 55 54 43;$, now=1527108550.000000000, _sid=1527108550.15, site=default, _api_et=1527019200.000000000, _api_lt=1527108550.000000000, _dsi_id=0, _keySet=dghsd index::test1, _ppc.bs=$SPLUNK_ETC, _search=search index=test1 dghsd, _shp_id=C0F05B71-38F6-4B2F-ACF7-5756DCD4CAB6, _endTime=1527108550.000000000, _ppc.app=search, read_raw=1, realtime=0, _countMap=duration.command.search.expand_search;39;duration.command.search.parse_directives;0;duration.dispatch.evaluate.search;54;duration.startup.configuration;11;duration.startup.handoff;3;invocations.command.search.expand_search;1;invocations.command.search.parse_directives;1;invocations.dispatch.evaluate.search;1;invocations.startup.configuration;1;invocations.startup.handoff;1;, _ppc.user=admin, check_dangerous_command=0, _default_group=&lt;EM&gt;, generation_id=0, _bundle_version=0, indexed_realtime=0, search_can_be_event_type=1, indexed_realtime_offset=0, kv_store_settings=hosts;127.0.0.1:8191\;;local;127.0.0.1:8191;read_preference;C0F05B71-38F6-4B2F-ACF7-5756DCD4CAB6;replica_set_name;C0F05B71-38F6-4B2F-ACF7-5756DCD4CAB6;status;ready;, _timeline_events_preview=0, is_cluster_slave=0, internal_only=0, is_batch_mode=0, _remote_search=search (index=test1 dghsd) | fields keepcolorder=t "&lt;/EM&gt;" "_bkt" "_cd" "_si" "host" "index" "linecount" "source" "sourcetype" "splunk_server", summary_stopped=0, _search_metrics={"ConsideredBuckets":0,"EliminatedBuckets":0,"ConsideredEvents":0,"TotalSlicesInBuckets":0,"DecompressedSlices":0,"FieldMetadata_Events":"","Partition":{}}, _is_summary_index=0, _search_StartUp_Spent=0, _is_keepalive=0, _is_scheduled=0, _splunkd_port=8089, _is_export=0, _is_remote=0, _maxevents=0, _search_et=1527019200.000000000, _search_lt=1527108550.000000000, _startTime=1527019200.000000000, _timestamp=1527108550.251636000, is_saved_search=0, is_remote_sorted=0, _search_StartTime=1527108550.250084000, remote_log_download_mode=disabledSavedSearches, kv_store_additional_settings=hosts_guids;C0F05B71-38F6-4B2F-ACF7-5756DCD4CAB6\;;, _rt_batch_retry=0, _auth_token=8cntqHuq0Rb0Lz3T^YcThKI7mBeHBy4ki7SPCQHDHCuMQq1haa4BENOHDqd43diGvYDkRlyNuR6xs1eUwYfPE4PBO1IeTwbkxIAG2JxOpUIpE^IOBBwklXUWaqa, _drop_count=0, _provenance=UI:Search, _scan_count=0, is_shc_mode=0, rt_backfill=0, sample_seed=0, _bs_thread_count=1, _retry_count=0, _splunkd_uri=&lt;A href="https://127.0.0.1:8089" target="_blank"&gt;https://127.0.0.1:8089&lt;/A&gt;, replay_speed=0, _exported_results=0, sample_ratio=1, summary_mode=none, _query_finished=1, _optional_fields_json={}, enable_event_stream=1, _splunkd_protocol=https, _read_buckets_since_startup=0, _bs_pipeline_identifier=0, _request_finalization=0}&lt;BR /&gt;
05-23-2018 20:49:13.581 ERROR ERP.maproly -     at com.splunk.mr.SplunkMR.getSummaryId(SplunkMR.java:507)&lt;BR /&gt;
05-23-2018 20:49:13.581 ERROR ERP.maproly -     at com.splunk.mr.SplunkMR$SearchHandler.executeMapReduce(SplunkMR.java:1359)&lt;BR /&gt;
05-23-2018 20:49:13.581 ERROR ERP.maproly -     at com.splunk.mr.SplunkMR$SearchHandler.executeImpl(SplunkMR.java:1067)&lt;BR /&gt;
05-23-2018 20:49:13.581 ERROR ERP.maproly -     at com.splunk.mr.SplunkMR$SearchHandler.execute(SplunkMR.java:906)&lt;BR /&gt;
05-23-2018 20:49:13.581 ERROR ERP.maproly -     at com.splunk.mr.SplunkMR.runImpl(SplunkMR.java:1802)&lt;BR /&gt;
05-23-2018 20:49:13.581 ERROR ERP.maproly -     at com.splunk.mr.SplunkMR.run(SplunkMR.java:1551)&lt;BR /&gt;
05-23-2018 20:49:13.581 ERROR ERP.maproly -     ... 3 more&lt;BR /&gt;
05-23-2018 20:49:13.597 INFO  ERP.maproly -  SplunkMR - finishing, version=6.2 ...&lt;BR /&gt;
05-23-2018 20:49:13.597 INFO  ERP.maproly -  DispatchReaper - Skip dispatch reaping, top level HDFS dispatch dir=/user/root/splunk/splunkmr/dispatch does not exist.&lt;BR /&gt;
05-23-2018 20:49:13.621 ERROR ERP.maproly -   Error while invoking command: /opt/mapr/hadoop/hadoop-2.7.0/bin/hadoop com.splunk.mr.SplunkMR - Return code: 255&lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://community.splunk.com/storage/temp/250780-priovider.png" alt="alt text" /&gt;&lt;BR /&gt;
&lt;IMG src="https://community.splunk.com/storage/temp/250781-virtual-index.png" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:37:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409275#M7078</guid>
      <dc:creator>EricLloyd79</dc:creator>
      <dc:date>2020-09-29T19:37:11Z</dc:date>
    </item>
    <item>
      <title>Re: Error invoking commnad: hadoop com.splunk.mr.SplunkMR - Return code: 255</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409276#M7079</link>
      <description>&lt;P&gt;It looks as if you are using TaskTracker and not Yarn.&lt;BR /&gt;
Change your settings to Yarn and point to Yarn resource Manager instead of Task Tracker. &lt;BR /&gt;
You are using Hadoop 2.7, which default to Yarn. &lt;BR /&gt;
In addition, your path to data in HDFS looks wrong. Normally all you need is /user/username&lt;BR /&gt;&lt;BR /&gt;
To test if you have the right location of the file in HDFS, I will recommend for you to try this command from CLI:&lt;BR /&gt;
hadoop fs -ls maprfs:///user/mapr &lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2018 14:04:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409276#M7079</guid>
      <dc:creator>rdagan_splunk</dc:creator>
      <dc:date>2018-05-24T14:04:13Z</dc:date>
    </item>
    <item>
      <title>Re: Error invoking commnad: hadoop com.splunk.mr.SplunkMR - Return code: 255</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409277#M7080</link>
      <description>&lt;P&gt;Thank you for your reply. Do you know how I can discover the path to my Yarn Resource Manager?&lt;/P&gt;

&lt;P&gt;Its interesting you say that the location of the file in HDFS is wrong because that is definitely where it is. I am also able to bring up that data via that directory with a simple query of "index=test" so it is finding it.&lt;BR /&gt;
When I run your command I get:&lt;/P&gt;

&lt;P&gt;[root@hadoop-s1 elloyd]# hadoop fs -ls maprfs:///user/mapr&lt;BR /&gt;
Found 22 items&lt;BR /&gt;
drwxr-xr-x   - root root          1 2018-05-23 21:57 maprfs:///user/mapr/2018&lt;BR /&gt;
drwxr-xr-x   - mapr mapr          1 2018-05-10 00:56 maprfs:///user/mapr/drill&lt;BR /&gt;
-rw-r--r--   3 root root          0 2018-05-24 14:00 maprfs:///user/mapr/dzl.log&lt;BR /&gt;
-rw-r--r--   3 root root          0 2018-05-23 22:00 maprfs:///user/mapr/dzl.log-20180523220001&lt;BR /&gt;
-rw-r--r--   3 root root          0 2018-05-23 23:00 maprfs:///user/mapr/dzl.log-20180523230001&lt;BR /&gt;
-rw-r--r--   3 root root          0 2018-05-24 00:00 maprfs:///user/mapr/dzl.log-20180524000001&lt;BR /&gt;
-rw-r--r--   3 root root          0 2018-05-24 01:00 maprfs:///user/mapr/dzl.log-20180524010002&lt;BR /&gt;
-rw-r--r--   3 root root          0 2018-05-24 02:00 maprfs:///user/mapr/dzl.log-20180524020001&lt;BR /&gt;
-rw-r--r--   3 root root          0 2018-05-24 03:00 maprfs:///user/mapr/dzl.log-20180524030001&lt;BR /&gt;
-rw-r--r--   3 root root          0 2018-05-24 04:00 maprfs:///user/mapr/dzl.log-20180524040001&lt;BR /&gt;
-rw-r--r--   3 root root          0 2018-05-24 05:00 maprfs:///user/mapr/dzl.log-20180524050002&lt;BR /&gt;
-rw-r--r--   3 root root          0 2018-05-24 06:00 maprfs:///user/mapr/dzl.log-20180524060002&lt;BR /&gt;
-rw-r--r--   3 root root          0 2018-05-24 07:00 maprfs:///user/mapr/dzl.log-20180524070001&lt;BR /&gt;
-rw-r--r--   3 root root          0 2018-05-24 08:00 maprfs:///user/mapr/dzl.log-20180524080001&lt;BR /&gt;
-rw-r--r--   3 root root          0 2018-05-24 09:00 maprfs:///user/mapr/dzl.log-20180524090001&lt;BR /&gt;
-rw-r--r--   3 root root          0 2018-05-24 10:00 maprfs:///user/mapr/dzl.log-20180524100001&lt;BR /&gt;
-rw-r--r--   3 root root          0 2018-05-24 11:00 maprfs:///user/mapr/dzl.log-20180524110002&lt;BR /&gt;
-rw-r--r--   3 root root          0 2018-05-24 12:00 maprfs:///user/mapr/dzl.log-20180524120001&lt;BR /&gt;
-rw-r--r--   3 root root          0 2018-05-24 13:00 maprfs:///user/mapr/dzl.log-20180524130001&lt;BR /&gt;
-rw-r--r--   3 root root          0 2018-05-24 14:00 maprfs:///user/mapr/dzl.log-20180524140001&lt;BR /&gt;
-rwxrwxrwx   3 root root    1283968 2018-05-23 17:48 maprfs:///user/mapr/test&lt;BR /&gt;
drwxr-xr-x   - mapr mapr          1 2018-05-10 00:58 maprfs:///user/mapr/tmp&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2018 14:46:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409277#M7080</guid>
      <dc:creator>EricLloyd79</dc:creator>
      <dc:date>2018-05-24T14:46:45Z</dc:date>
    </item>
    <item>
      <title>Re: Error invoking commnad: hadoop com.splunk.mr.SplunkMR - Return code: 255</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409278#M7081</link>
      <description>&lt;P&gt;Well, I have changed these:&lt;BR /&gt;
Hadoop 2.x, Yarn&lt;BR /&gt;
resource manager:   localhost:8032&lt;BR /&gt;
resource scheduler: localhost:8030&lt;/P&gt;

&lt;P&gt;And changed my HDFS address to /user/mapr&lt;/P&gt;

&lt;P&gt;I am still able to bring results on: "index=test"&lt;BR /&gt;
but still getting the same error with "index=test foo"&lt;/P&gt;

&lt;P&gt;so nothing changed &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2018 15:32:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409278#M7081</guid>
      <dc:creator>EricLloyd79</dc:creator>
      <dc:date>2018-05-24T15:32:40Z</dc:date>
    </item>
    <item>
      <title>Re: Error invoking commnad: hadoop com.splunk.mr.SplunkMR - Return code: 255</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409279#M7082</link>
      <description>&lt;P&gt;When I do a search for com.splunk.mr.SplunkMR on my linux system, it finds nothing.  Perhaps it is missing this but Im unsure how that would be missing I figure it came with the Splunk install&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2018 15:54:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409279#M7082</guid>
      <dc:creator>EricLloyd79</dc:creator>
      <dc:date>2018-05-24T15:54:16Z</dc:date>
    </item>
    <item>
      <title>Re: Error invoking commnad: hadoop com.splunk.mr.SplunkMR - Return code: 255</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409280#M7083</link>
      <description>&lt;P&gt;What version of Splunk are you using?&lt;BR /&gt;
When you go to '  &lt;A href="http://localhost:8088/conf"&gt;http://localhost:8088/conf&lt;/A&gt;  ' you should be able to see all the correct values for the Yarn Resource Manager &lt;BR /&gt;
yarn.resourcemanager.address  and yarn.resourcemanager.scheduler.address &lt;BR /&gt;
Can you try to run index=test1 | stats count &lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2018 17:15:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409280#M7083</guid>
      <dc:creator>rdagan_splunk</dc:creator>
      <dc:date>2018-05-24T17:15:40Z</dc:date>
    </item>
    <item>
      <title>Re: Error invoking commnad: hadoop com.splunk.mr.SplunkMR - Return code: 255</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409281#M7084</link>
      <description>&lt;P&gt;Splunk 7.1&lt;BR /&gt;
I go to that link (change out localhost for our host name where this is running) and it says it refuses to connect.  ERR_CONNECTION_REFUSED&lt;/P&gt;

&lt;P&gt;Interestingly enough, your query index=test1 | stats count does produce a result but then also gives an error:&lt;/P&gt;

&lt;P&gt;[maproly] Error while running external process, return_code=255. See search.log for more info&lt;BR /&gt;
[maproly] Exception - java.io.IOException: Error while waiting for MapReduce job to complete, job_id=job_1525914386605_0002, state=FAILED, reason=Application application_1525914386605_0002 failed 2 times due to AM Container for appattempt_1525914386605_0002_000002 exited with exitCode: -1000&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:37:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409281#M7084</guid>
      <dc:creator>EricLloyd79</dc:creator>
      <dc:date>2020-09-29T19:37:41Z</dc:date>
    </item>
    <item>
      <title>Re: Error invoking commnad: hadoop com.splunk.mr.SplunkMR - Return code: 255</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409282#M7085</link>
      <description>&lt;P&gt;Hi rdagan, we're using splunk 7.10. &lt;/P&gt;

&lt;P&gt;:8088/conf doesn't work. that port is closed. &lt;/P&gt;

&lt;P&gt;https on port 8089 works as expected but /conf is not found.&lt;/P&gt;

&lt;P&gt;:8089/services/configs is the closest thing i could find and i don't see any Yarn stuff.&lt;/P&gt;

&lt;P&gt;Running stats count gives us a slightly different (and shorter) error:&lt;/P&gt;

&lt;P&gt;2 errors occurred while the search was executing. Therefore, search results might be incomplete. Hide errors.&lt;BR /&gt;
[maproly] Error while running external process, return_code=255. See search.log for more info&lt;BR /&gt;
[maproly] Exception - java.io.IOException: Error while waiting for MapReduce job to complete, job_id=job_1525914386605_0005, state=FAILED, reason=Application application_1525914386605_0005 failed 2 times due to AM Container for appattempt_1525914386605_0005_000002 exited with exitCode: -1000&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:41:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409282#M7085</guid>
      <dc:creator>gozulin</dc:creator>
      <dc:date>2020-09-29T19:41:20Z</dc:date>
    </item>
    <item>
      <title>Re: Error invoking commnad: hadoop com.splunk.mr.SplunkMR - Return code: 255</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409283#M7086</link>
      <description>&lt;P&gt;rdagan:&lt;BR /&gt;
The error in our logs is:&lt;BR /&gt;
05-24-2018 17:54:24.799 ERROR ERP.maproly -   Error while invoking command: /opt/mapr/hadoop/hadoop-2.7.0/bin/hadoop com.splunk.mr.SplunkMR - Return code: 255&lt;/P&gt;

&lt;P&gt;And when I try to run the class manually I get:&lt;/P&gt;

&lt;P&gt;[root@hadoop-s1 log-gen]# /opt/mapr/hadoop/hadoop-2.7.0/bin/hadoop com.splunk.mr.SplunkMR&lt;BR /&gt;
Error: Could not find or load main class com.splunk.mr.SplunkMR&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2018 18:01:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409283#M7086</guid>
      <dc:creator>EricLloyd79</dc:creator>
      <dc:date>2018-05-24T18:01:22Z</dc:date>
    </item>
    <item>
      <title>Re: Error invoking commnad: hadoop com.splunk.mr.SplunkMR - Return code: 255</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409284#M7087</link>
      <description>&lt;P&gt;We will need to dig into the Hadoop log - specifically the hadoop Attempt log - to see the actual error&lt;/P&gt;

&lt;P&gt;Exception - java.io.IOException: Error while waiting for MapReduce job to complete, job_id=job_1525914386605_0005, state=FAILED, reason=Application application_1525914386605_0005 failed 2 times due to AM Container for appattempt_1525914386605_0005_000002 exited with exitCode: -1000&lt;/P&gt;

&lt;P&gt;Normally &lt;A href="http://Yarn" target="_blank"&gt;http://Yarn&lt;/A&gt; Resource Manager IP: 8088 should take you to the main Hadoop Yarn page&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:37:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409284#M7087</guid>
      <dc:creator>rdagan_splunk</dc:creator>
      <dc:date>2020-09-29T19:37:47Z</dc:date>
    </item>
    <item>
      <title>Re: Error invoking commnad: hadoop com.splunk.mr.SplunkMR - Return code: 255</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409285#M7088</link>
      <description>&lt;P&gt;Try to run this command to find which jars contain the above class.  And then see if that jar is in the  Hadoop classpath&lt;BR /&gt;
find . -name "*.jar" -exec grep -Hsli com.splunk.mr.SplunkMR {} \;&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2018 20:39:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409285#M7088</guid>
      <dc:creator>rdagan_splunk</dc:creator>
      <dc:date>2018-05-24T20:39:00Z</dc:date>
    </item>
    <item>
      <title>Re: Error invoking commnad: hadoop com.splunk.mr.SplunkMR - Return code: 255</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409286#M7089</link>
      <description>&lt;P&gt;So I added it to the Hadoop classpath, rdagan and i see a promising result running the jar from the command line:&lt;BR /&gt;
[root@hadoop-s1 /]# /opt/mapr/hadoop/hadoop-2.7.0/bin/hadoop com.splunk.mr.SplunkMR&lt;BR /&gt;
INFO SplunkMR - starting, version=6.2 ...&lt;/P&gt;

&lt;P&gt;But when I run the search I still get the same error and even get this again...&lt;/P&gt;

&lt;P&gt;05-24-2018 20:46:29.179 ERROR ERP.maproly -   Error while invoking command: /opt/mapr/hadoop/hadoop-2.7.0/bin/hadoop com.splunk.mr.SplunkMR - Return code: 255&lt;/P&gt;

&lt;P&gt;Now Im starting to wonder if it isnt some kind of permissions thing but Im running the command in CLI as root and the splunk query I think is being run by root&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2018 20:50:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409286#M7089</guid>
      <dc:creator>EricLloyd79</dc:creator>
      <dc:date>2018-05-24T20:50:47Z</dc:date>
    </item>
    <item>
      <title>Re: Error invoking commnad: hadoop com.splunk.mr.SplunkMR - Return code: 255</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409287#M7090</link>
      <description>&lt;P&gt;Update:&lt;/P&gt;

&lt;P&gt;If I run the search from the command line with:&lt;BR /&gt;
 /opt/splunk/bin/splunk search index=test1 Exiting&lt;/P&gt;

&lt;P&gt;It seems to produce results without the error but then all of splunk is now producing no results.  haha  &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;BR /&gt;
[maproly] IOException - Out of memory error while reading a very large single line input record. To skip this record set mapreduce.input.linerecordreader.line.maxlength to a lower value. Current value: 2147483647, jvm heap size: 508035072, potential value: 31752192&lt;/P&gt;

&lt;P&gt;Working on changing the mapreduce.input.linerecordreader.line.maxlength&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2018 21:09:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409287#M7090</guid>
      <dc:creator>EricLloyd79</dc:creator>
      <dc:date>2018-05-24T21:09:35Z</dc:date>
    </item>
    <item>
      <title>Re: Error invoking commnad: hadoop com.splunk.mr.SplunkMR - Return code: 255</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409288#M7091</link>
      <description>&lt;P&gt;Okay, fixed the unusual maxlength error... back to being able run the Splunk queries such as "index=test Exiting" from the CLI but not from the web UI due to the same error.&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2018 21:26:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409288#M7091</guid>
      <dc:creator>EricLloyd79</dc:creator>
      <dc:date>2018-05-24T21:26:41Z</dc:date>
    </item>
    <item>
      <title>Re: Error invoking commnad: hadoop com.splunk.mr.SplunkMR - Return code: 255</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409289#M7092</link>
      <description>&lt;P&gt;Make sure the classpath in the Provider is the same as your Hadoop envirnment:&lt;BR /&gt;
Specifically I am thinking about these two&lt;BR /&gt;
vix.yarn.application.classpath&lt;BR /&gt;
vix.mapreduce.application.classpath&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Hunk/6.4.10/Hunk/RequiredConfigurationVariablesforYARN"&gt;https://docs.splunk.com/Documentation/Hunk/6.4.10/Hunk/RequiredConfigurationVariablesforYARN&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 25 May 2018 05:34:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409289#M7092</guid>
      <dc:creator>rdagan_splunk</dc:creator>
      <dc:date>2018-05-25T05:34:02Z</dc:date>
    </item>
    <item>
      <title>Re: Error invoking commnad: hadoop com.splunk.mr.SplunkMR - Return code: 255</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409290#M7093</link>
      <description>&lt;P&gt;Sorry I guess I am unclear what the classpath in the Provider is...?  do you mean vix.arg.1=$HADOOP_HOME/bin/hadoop&lt;/P&gt;</description>
      <pubDate>Fri, 25 May 2018 17:00:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409290#M7093</guid>
      <dc:creator>EricLloyd79</dc:creator>
      <dc:date>2018-05-25T17:00:59Z</dc:date>
    </item>
    <item>
      <title>Re: Error invoking commnad: hadoop com.splunk.mr.SplunkMR - Return code: 255</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409291#M7094</link>
      <description>&lt;P&gt;I bet you mean this: /opt/mapr/hadoop/hadoop-2.7.0&lt;/P&gt;</description>
      <pubDate>Fri, 25 May 2018 17:31:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409291#M7094</guid>
      <dc:creator>EricLloyd79</dc:creator>
      <dc:date>2018-05-25T17:31:11Z</dc:date>
    </item>
    <item>
      <title>Re: Error invoking commnad: hadoop com.splunk.mr.SplunkMR - Return code: 255</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409292#M7095</link>
      <description>&lt;P&gt;Well I added them to the yarn-site.xml and the error persists.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;name&amp;gt;vix.yarn.application.classpath&amp;lt;/name&amp;gt;
&amp;lt;value&amp;gt;/opt/mapr/hadoop/hadoop-2.7.0&amp;lt;/value&amp;gt;



&amp;lt;name&amp;gt;vix.mapreduce.application.classpath&amp;lt;/name&amp;gt;
&amp;lt;value&amp;gt;/opt/mapr/hadoop/hadoop-2.7.0&amp;lt;/value&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 25 May 2018 17:34:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409292#M7095</guid>
      <dc:creator>EricLloyd79</dc:creator>
      <dc:date>2018-05-25T17:34:13Z</dc:date>
    </item>
    <item>
      <title>Re: Error invoking commnad: hadoop com.splunk.mr.SplunkMR - Return code: 255</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409293#M7096</link>
      <description>&lt;P&gt;The vix.mapreduce.. and vix.yarn must be added to the Splunk provider. At the bottom of the Provider GUI you will see the add variables option.&lt;/P&gt;</description>
      <pubDate>Fri, 25 May 2018 20:29:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409293#M7096</guid>
      <dc:creator>rdagan_splunk</dc:creator>
      <dc:date>2018-05-25T20:29:45Z</dc:date>
    </item>
    <item>
      <title>Re: Error invoking commnad: hadoop com.splunk.mr.SplunkMR - Return code: 255</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409294#M7097</link>
      <description>&lt;P&gt;Well I added them to the variables in the Provider on Splunk UI and the error still exists.&lt;BR /&gt;
I have submitted a ticket with Splunk Support but they dont seem to be responding. I guess maybe everyone is already in their 3 day Memorial Day Weekend. Maybe I should be too. &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 May 2018 21:29:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Error-invoking-commnad-hadoop-com-splunk-mr-SplunkMR-Return-code/m-p/409294#M7097</guid>
      <dc:creator>EricLloyd79</dc:creator>
      <dc:date>2018-05-25T21:29:23Z</dc:date>
    </item>
  </channel>
</rss>

