<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Could not understand Splunkd.log in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Could-not-understand-Splunkd-log/m-p/78201#M16003</link>
    <description>&lt;P&gt;i am not sure as it doesnot seems to be linked to any of the above or below events...you might need to put log level to DEBUG for the AdminManager...&lt;/P&gt;</description>
    <pubDate>Fri, 04 Jan 2013 15:59:04 GMT</pubDate>
    <dc:creator>MarioM</dc:creator>
    <dc:date>2013-01-04T15:59:04Z</dc:date>
    <item>
      <title>Could not understand Splunkd.log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Could-not-understand-Splunkd-log/m-p/78198#M16000</link>
      <description>&lt;P&gt;I see the below in splunkd.log&lt;/P&gt;

&lt;P&gt;ERROR AdminManager - Argument "timeout" is not supported by this handler.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;UPDATE&lt;/STRONG&gt;&lt;BR /&gt;
&lt;PRE&gt;&lt;BR /&gt;
&lt;CODE&gt;&lt;BR /&gt;
01-04-2013 08:04:10.394 +0000 INFO  AdminManager - adding validation:savedsearch validation rule alert.severity='alert.severity'&amp;gt;0 AND 'alert.severity'&amp;lt;7 ...&lt;BR /&gt;
01-04-2013 08:04:10.394 +0000 INFO  AdminManager - adding validation:savedsearch validation rule alert.suppress=validate( is_bool('alert.suppress'),          "Value of argument 'alert.suppress' must be a boolean") ...&lt;BR /&gt;
01-04-2013 08:04:10.394 +0000 INFO  AdminManager - adding validation:savedsearch validation rule alert.suppress.period=validate ( match('alert.suppress.period', "(?i)^(ack)|(\d+[hmsd]?)$"), "Value of argument alert.suppress.period must be of the format &lt;INTEGER&gt;[smhd]? or ack") ...&lt;BR /&gt;
01-04-2013 08:04:10.399 +0000 INFO  AdminManager - hId=/saved/searches, feedName=savedsearch, atomUrl=servicesNS/nbkbk7n/ecomm_splunk_env_monitoring&lt;BR /&gt;
01-04-2013 08:04:22.241 +0000 INFO  AdminManager - alias results: oldPath=/licenser/slaves, newPath=admin//slaves, handlerId=/licenser/slaves, tmpURL=/licenser&lt;BR /&gt;
01-04-2013 08:04:22.241 +0000 ERROR AdminManager - Argument "timeout" is not supported by this handler.&lt;BR /&gt;
01-04-2013 08:04:32.456 +0000 INFO  AdminManager - alias results: oldPath=/server/info, newPath=admin//server-info, handlerId=/server/info, tmpURL=/server&lt;BR /&gt;
01-04-2013 08:04:32.463 +0000 INFO  AdminManager - hId=/server/info, feedName=server-info, atomUrl=services&lt;BR /&gt;
01-04-2013 08:04:32.980 +0000 INFO  AdminManager - alias results: oldPath=/server/info, newPath=admin//server-info, handlerId=/server/info, tmpURL=/server&lt;BR /&gt;
01-04-2013 08:04:32.984 +0000 INFO  AdminManager - hId=/server/info, feedName=server-info, atomUrl=services&lt;BR /&gt;
01-04-2013 08:04:36.913 +0000 INFO  AdminManager - alias results: oldPath=/saved/searches/DM%20missing%20sourcetypes/notify, newPath=admin//savedsearch/DM%20missing%20sourcetypes/notify, handlerId=/saved/searches, tmpURL=/saved&lt;BR /&gt;
01-04-2013 08:04:36.915 +0000 INFO  AdminManager - adding validation rules from restmap.conf [validation:savedsearch]&lt;/INTEGER&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;/P&gt;

&lt;P&gt;&lt;BR /&gt;
&lt;/P&gt;

&lt;P&gt;What does it mean and how can i fix this.&lt;/P&gt;

&lt;P&gt;Anand&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:02:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Could-not-understand-Splunkd-log/m-p/78198#M16000</guid>
      <dc:creator>ma_anand1984</dc:creator>
      <dc:date>2020-09-28T13:02:53Z</dc:date>
    </item>
    <item>
      <title>Re: Could not understand Splunkd.log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Could-not-understand-Splunkd-log/m-p/78199#M16001</link>
      <description>&lt;P&gt;it sounds like you have an incorrect value in  &lt;CODE&gt;Manager&amp;gt;&amp;gt;System configurations&amp;gt;&amp;gt;System settings&amp;gt;&amp;gt;General settings&amp;gt;&amp;gt;System timeout field&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jan 2013 07:37:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Could-not-understand-Splunkd-log/m-p/78199#M16001</guid>
      <dc:creator>MarioM</dc:creator>
      <dc:date>2013-01-04T07:37:52Z</dc:date>
    </item>
    <item>
      <title>Re: Could not understand Splunkd.log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Could-not-understand-Splunkd-log/m-p/78200#M16002</link>
      <description>&lt;P&gt;Thank you Mario. 1h is the value i'm having. I ran AdminManager in info mode and have the following. Please see update in Question&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jan 2013 08:15:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Could-not-understand-Splunkd-log/m-p/78200#M16002</guid>
      <dc:creator>ma_anand1984</dc:creator>
      <dc:date>2013-01-04T08:15:19Z</dc:date>
    </item>
    <item>
      <title>Re: Could not understand Splunkd.log</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Could-not-understand-Splunkd-log/m-p/78201#M16003</link>
      <description>&lt;P&gt;i am not sure as it doesnot seems to be linked to any of the above or below events...you might need to put log level to DEBUG for the AdminManager...&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jan 2013 15:59:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Could-not-understand-Splunkd-log/m-p/78201#M16003</guid>
      <dc:creator>MarioM</dc:creator>
      <dc:date>2013-01-04T15:59:04Z</dc:date>
    </item>
  </channel>
</rss>

