<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk errors and issues in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-Splunk-CIM-errors-and-issues/m-p/636244#M108826</link>
    <description>&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/2968" target="_blank"&gt;https://splunkbase.splunk.com/app/2968&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 28 Mar 2023 04:18:55 GMT</pubDate>
    <dc:creator>bowesmana</dc:creator>
    <dc:date>2023-03-28T04:18:55Z</dc:date>
    <item>
      <title>How to resolve Splunk CIM errors and issues?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-Splunk-CIM-errors-and-issues/m-p/636219#M108819</link>
      <description>&lt;P&gt;I am in a environment and I am able to get data in from a general perspective. We have a index clustered and search head clustered test&amp;nbsp; env&amp;nbsp; I can search *&amp;nbsp; and get data in andjust deal with that. we have the CIM vladiator app and we get&amp;nbsp; errors such as the following&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cim validator error.PNG" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/24566iB1F74520F7F211FB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="cim validator error.PNG" alt="cim validator error.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cim validator.PNG" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/24567i598CDAD7FFB75505/image-size/medium?v=v2&amp;amp;px=400" role="button" title="cim validator.PNG" alt="cim validator.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; So then I go and hunt the splunkd.log files of said location but really cant make heads or tails of whats important to solve any issues I may have.&lt;/P&gt;
&lt;P&gt;attached are  the splukd.log from sh01 and indx03,indx03 and indx04 respectively.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunk splunkd.log on SH01.PNG" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/24568iF8355F783839EE62/image-size/medium?v=v2&amp;amp;px=400" role="button" title="splunk splunkd.log on SH01.PNG" alt="splunk splunkd.log on SH01.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splunkd.log from indx02.PNG" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/24569i8B4AEA94EDB4B9CE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="splunkd.log from indx02.PNG" alt="splunkd.log from indx02.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="indx03.PNG" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/24570iE6104A54A1AA0887/image-size/medium?v=v2&amp;amp;px=400" role="button" title="indx03.PNG" alt="indx03.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="indx04.PNG" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/24571iEAA96DBD4B748997/image-size/medium?v=v2&amp;amp;px=400" role="button" title="indx04.PNG" alt="indx04.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;  Should I care about info warning and should I worry about warnings or should I focus on errors?&lt;/P&gt;
&lt;P&gt;Keep in mind I have tried to search Some of these errors but they answers are amiguitous or not relevant or don't work.&lt;/P&gt;
&lt;P&gt; Is there a strategy that people use to go about this ?&lt;/P&gt;
&lt;P&gt;is there anything that is seen on here that stands out?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 01:06:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-Splunk-CIM-errors-and-issues/m-p/636219#M108819</guid>
      <dc:creator>domino30</dc:creator>
      <dc:date>2023-03-28T01:06:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk errors and issues</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-Splunk-CIM-errors-and-issues/m-p/636223#M108821</link>
      <description>&lt;P&gt;It says that SA_CIM_validator cannot be found on the indexers. Is the app installed on them? Some apps need to be deployed on the indexers too, but not sure what else may be relevant or if that's necessary here.&lt;/P&gt;&lt;P&gt;Errno 111 = Connection Refused?&lt;/P&gt;&lt;P&gt;Can't offer much more I'm afraid.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2023 22:20:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-Splunk-CIM-errors-and-issues/m-p/636223#M108821</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2023-03-27T22:20:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk errors and issues</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-Splunk-CIM-errors-and-issues/m-p/636228#M108823</link>
      <description>&lt;P&gt;&lt;STRIKE&gt;Notice the spelling. The screenshot says "SA-cim_vladiator", not "validator".&lt;/STRIKE&gt;&lt;/P&gt;&lt;P&gt;&lt;STRIKE&gt;There is much more going on underneath than meets the eye I'm afraid. Someone must have hurt this environment...&lt;/STRIKE&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 08:43:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-Splunk-CIM-errors-and-issues/m-p/636228#M108823</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-03-28T08:43:53Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk errors and issues</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-Splunk-CIM-errors-and-issues/m-p/636244#M108826</link>
      <description>&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/2968" target="_blank"&gt;https://splunkbase.splunk.com/app/2968&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 04:18:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-Splunk-CIM-errors-and-issues/m-p/636244#M108826</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2023-03-28T04:18:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk errors and issues</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-Splunk-CIM-errors-and-issues/m-p/636253#M108828</link>
      <description>&lt;P&gt;Oh, my bad. Seemed like a typo more than a legitimate name.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 06:51:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-Splunk-CIM-errors-and-issues/m-p/636253#M108828</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-03-28T06:51:25Z</dc:date>
    </item>
  </channel>
</rss>

