<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: In splunkd.log, why do I receive repeating error &amp;quot;ERROR KVStorageProvider - An error occurred during the last operation...Cannot do an empty bulk write&amp;quot;? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/In-splunkd-log-why-do-I-receive-repeating-error-quot-ERROR/m-p/345702#M63515</link>
    <description>&lt;P&gt;Hi Bnorthway,&lt;/P&gt;

&lt;P&gt;I think I have the exact same issue as yours. The POST is realated to DA-ESS-ThreatIntelligence.&lt;/P&gt;

&lt;P&gt;And I also have ERROR message complaining some threat intelligence download has failed:&lt;BR /&gt;
emerging_threats_ip_blocklist&lt;BR /&gt;
iblocklist_tor&lt;BR /&gt;
emerging_threats_ip_blocklist&lt;BR /&gt;
iblocklist_tor&lt;/P&gt;

&lt;P&gt;Many thanks&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 13:10:58 GMT</pubDate>
    <dc:creator>season88481</dc:creator>
    <dc:date>2020-09-29T13:10:58Z</dc:date>
    <item>
      <title>In splunkd.log, why do I receive repeating error "ERROR KVStorageProvider - An error occurred during the last operation...Cannot do an empty bulk write"?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/In-splunkd-log-why-do-I-receive-repeating-error-quot-ERROR/m-p/345700#M63513</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;ERROR KVStorageProvider - An error occurred during the last operation ('saveBatchData', domain: '11', code: '22'): Cannot do an empty bulk write
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This error is repeated in splunkd.log. The search head cluster appears to be functional but I am concerned about the cause of this error.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2017 19:53:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/In-splunkd-log-why-do-I-receive-repeating-error-quot-ERROR/m-p/345700#M63513</guid>
      <dc:creator>bnorthway_splun</dc:creator>
      <dc:date>2017-03-10T19:53:34Z</dc:date>
    </item>
    <item>
      <title>Re: In splunkd.log, why do I receive repeating error "ERROR KVStorageProvider - An error occurred during the last operation...Cannot do an empty bulk write"?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/In-splunkd-log-why-do-I-receive-repeating-error-quot-ERROR/m-p/345701#M63514</link>
      <description>&lt;P&gt;This error indicates that a POST request has an empty json body. Try this search to find the offending request:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;index=_internal sourcetype=splunkd_access batch_save status=500&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;In my case, Enterprise Security threat lists were failing to download and causing this error.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:10:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/In-splunkd-log-why-do-I-receive-repeating-error-quot-ERROR/m-p/345701#M63514</guid>
      <dc:creator>bnorthway_splun</dc:creator>
      <dc:date>2020-09-29T13:10:14Z</dc:date>
    </item>
    <item>
      <title>Re: In splunkd.log, why do I receive repeating error "ERROR KVStorageProvider - An error occurred during the last operation...Cannot do an empty bulk write"?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/In-splunkd-log-why-do-I-receive-repeating-error-quot-ERROR/m-p/345702#M63515</link>
      <description>&lt;P&gt;Hi Bnorthway,&lt;/P&gt;

&lt;P&gt;I think I have the exact same issue as yours. The POST is realated to DA-ESS-ThreatIntelligence.&lt;/P&gt;

&lt;P&gt;And I also have ERROR message complaining some threat intelligence download has failed:&lt;BR /&gt;
emerging_threats_ip_blocklist&lt;BR /&gt;
iblocklist_tor&lt;BR /&gt;
emerging_threats_ip_blocklist&lt;BR /&gt;
iblocklist_tor&lt;/P&gt;

&lt;P&gt;Many thanks&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:10:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/In-splunkd-log-why-do-I-receive-repeating-error-quot-ERROR/m-p/345702#M63515</guid>
      <dc:creator>season88481</dc:creator>
      <dc:date>2020-09-29T13:10:58Z</dc:date>
    </item>
    <item>
      <title>Re: In splunkd.log, why do I receive repeating error "ERROR KVStorageProvider - An error occurred during the last operation...Cannot do an empty bulk write"?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/In-splunkd-log-why-do-I-receive-repeating-error-quot-ERROR/m-p/345703#M63516</link>
      <description>&lt;P&gt;I found if there is a lookup file located at $SPLUNK_HOME/splunk/etc/apps/DA-ESS-ThreatIntelligence/local/data/threat_intel, such error will pop-up.&lt;/P&gt;

&lt;P&gt;Then I mv my local_ip_intel.csv file to local_ip_intel.bak. Error message seems stop showing up. Anyone could explain what happen here?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:19:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/In-splunkd-log-why-do-I-receive-repeating-error-quot-ERROR/m-p/345703#M63516</guid>
      <dc:creator>season88481</dc:creator>
      <dc:date>2020-09-29T14:19:20Z</dc:date>
    </item>
  </channel>
</rss>

