<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WARN  CMHeartbeatThread what is this error telling me? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/WARN-CMHeartbeatThread-what-is-this-error-telling-me/m-p/430952#M75425</link>
    <description>&lt;P&gt;Hi thank you for the answer.&lt;/P&gt;

&lt;P&gt;I can´t answer the question, the file seems to be temporay, and its deleted pretty fast.&lt;/P&gt;

&lt;P&gt;But I do see folders named like "DM_Splunk_SA_CIM_Authentication" with files like :   done  metadata_checksum  metadata.csv&lt;/P&gt;

&lt;P&gt;What can I do with these errors since there floding my splunkd.log I would like to get rid of them?&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 19:44:16 GMT</pubDate>
    <dc:creator>dkeck</dc:creator>
    <dc:date>2020-09-29T19:44:16Z</dc:date>
    <item>
      <title>WARN  CMHeartbeatThread what is this error telling me?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WARN-CMHeartbeatThread-what-is-this-error-telling-me/m-p/430950#M75423</link>
      <description>&lt;P&gt;HI &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;I see a lot of these errors on one of my Clusterindexer, its an indexer with legacy data (not replicated in cluster).&lt;/P&gt;

&lt;P&gt;Does anyone know what this is telling me? since I can´t find anything on answers or docs.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;WARN  CMHeartbeatThread - event=SummaryRegistration got unknown_state for summary at path=$SPLUNK_DB/&amp;lt;index_name&amp;gt;/datamodel_summary/0_B8208014-CC0D-484A-8304-72E85F04F7AF/1DA71394-60C4-4788-BDEB-31F414XXXX/DM_Splunk_SA_CIM_XXXX.smlock.&amp;lt;indexer_name&amp;gt;-9298.temp-140536340007468
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Sounds like the  SH(1DA71394-60C4-4788-BDEB-31F414XXXX) is trying to run something on this indexer?!&lt;/P&gt;

&lt;P&gt;Thank you &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 May 2018 12:32:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WARN-CMHeartbeatThread-what-is-this-error-telling-me/m-p/430950#M75423</guid>
      <dc:creator>dkeck</dc:creator>
      <dc:date>2018-05-30T12:32:39Z</dc:date>
    </item>
    <item>
      <title>Re: WARN  CMHeartbeatThread what is this error telling me?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WARN-CMHeartbeatThread-what-is-this-error-telling-me/m-p/430951#M75424</link>
      <description>&lt;P&gt;Its a no-op warning. The cluster will monitor for new summaries in the summary path (summaries are always folders). However, there are also temporary files in there (as the one listed above), that our code will log a WARNING against.&lt;/P&gt;

&lt;P&gt;edit - is that file a folder btw? seems like we already guard against it in code...&lt;/P&gt;</description>
      <pubDate>Wed, 30 May 2018 17:48:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WARN-CMHeartbeatThread-what-is-this-error-telling-me/m-p/430951#M75424</guid>
      <dc:creator>dxu_splunk</dc:creator>
      <dc:date>2018-05-30T17:48:03Z</dc:date>
    </item>
    <item>
      <title>Re: WARN  CMHeartbeatThread what is this error telling me?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/WARN-CMHeartbeatThread-what-is-this-error-telling-me/m-p/430952#M75425</link>
      <description>&lt;P&gt;Hi thank you for the answer.&lt;/P&gt;

&lt;P&gt;I can´t answer the question, the file seems to be temporay, and its deleted pretty fast.&lt;/P&gt;

&lt;P&gt;But I do see folders named like "DM_Splunk_SA_CIM_Authentication" with files like :   done  metadata_checksum  metadata.csv&lt;/P&gt;

&lt;P&gt;What can I do with these errors since there floding my splunkd.log I would like to get rid of them?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:44:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/WARN-CMHeartbeatThread-what-is-this-error-telling-me/m-p/430952#M75425</guid>
      <dc:creator>dkeck</dc:creator>
      <dc:date>2020-09-29T19:44:16Z</dc:date>
    </item>
  </channel>
</rss>

