<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Search process did not exit cleanly, exit_code=255, description=&amp;quot;exited with code 255 in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Search-process-did-not-exit-cleanly-exit-code-255-description/m-p/421003#M6643</link>
    <description>&lt;P&gt;Dear everyone,&lt;BR /&gt;
Have a good day ahead.&lt;/P&gt;

&lt;P&gt;I am having the following issue that need your advice. Recently, I have deployed Splunk in distributed environment as the following:&lt;BR /&gt;
- 01 Master + License master&lt;BR /&gt;
- 01 Search Head&lt;BR /&gt;
- 02 Indexer&lt;BR /&gt;
- 01 Heavy Forwarder&lt;/P&gt;

&lt;P&gt;Without installing app on Search Head, the application is working fine without any error. However, whenever I install app on SH, the following error is appeared for one of our Indexing system:&lt;BR /&gt;
"Search process did not exit cleanly, exit_code=255, description="exited with code 255". Please look in search.log for this peer in the Job Inspector for more info."&lt;/P&gt;

&lt;P&gt;By checking the search.log, we see a lot of the following error:&lt;BR /&gt;
12-03-2018 14:53:28.293 INFO ReducePhaseExecutor - ReducePhaseExecutor=1 action=PREVIEW&lt;BR /&gt;
12-03-2018 14:53:28.701 ERROR SRSSerializer - could not read number of columns&lt;BR /&gt;
12-03-2018 14:53:28.701 WARN SRSSerializer - could not read schema&lt;BR /&gt;
12-03-2018 14:53:28.723 INFO TimelineCreator - Commit timeline at cursor=1543804147.000000&lt;BR /&gt;
12-03-2018 14:53:28.724 INFO ReducePhaseExecutor - ReducePhaseExecutor=1 action=PREVIEW&lt;BR /&gt;
12-03-2018 14:53:29.073 ERROR SRSSerializer - could not read number of columns&lt;BR /&gt;
12-03-2018 14:53:29.073 WARN SRSSerializer - could not read schema&lt;BR /&gt;
12-03-2018 14:53:29.095 INFO TimelineCreator - Commit timeline at cursor=1543803804.000000&lt;BR /&gt;
12-03-2018 14:53:29.096 INFO ReducePhaseExecutor - ReducePhaseExecutor=1 action=PREVIEW&lt;BR /&gt;
12-03-2018 14:53:29.601 ERROR SRSSerializer - could not read number of columns&lt;BR /&gt;
12-03-2018 14:53:29.601 WARN SRSSerializer - could not read schema&lt;/P&gt;

&lt;P&gt;Due to this error, I cannot search any event which is indexed by the problematic node.&lt;BR /&gt;
Can you please advice how I should proceed further to fix this issue?&lt;/P&gt;

&lt;P&gt;Thank you for your time in advance.&lt;BR /&gt;
Regards,&lt;BR /&gt;
Anh&lt;/P&gt;</description>
    <pubDate>Mon, 03 Dec 2018 08:15:10 GMT</pubDate>
    <dc:creator>lybinhlap</dc:creator>
    <dc:date>2018-12-03T08:15:10Z</dc:date>
    <item>
      <title>Search process did not exit cleanly, exit_code=255, description="exited with code 255</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Search-process-did-not-exit-cleanly-exit-code-255-description/m-p/421003#M6643</link>
      <description>&lt;P&gt;Dear everyone,&lt;BR /&gt;
Have a good day ahead.&lt;/P&gt;

&lt;P&gt;I am having the following issue that need your advice. Recently, I have deployed Splunk in distributed environment as the following:&lt;BR /&gt;
- 01 Master + License master&lt;BR /&gt;
- 01 Search Head&lt;BR /&gt;
- 02 Indexer&lt;BR /&gt;
- 01 Heavy Forwarder&lt;/P&gt;

&lt;P&gt;Without installing app on Search Head, the application is working fine without any error. However, whenever I install app on SH, the following error is appeared for one of our Indexing system:&lt;BR /&gt;
"Search process did not exit cleanly, exit_code=255, description="exited with code 255". Please look in search.log for this peer in the Job Inspector for more info."&lt;/P&gt;

&lt;P&gt;By checking the search.log, we see a lot of the following error:&lt;BR /&gt;
12-03-2018 14:53:28.293 INFO ReducePhaseExecutor - ReducePhaseExecutor=1 action=PREVIEW&lt;BR /&gt;
12-03-2018 14:53:28.701 ERROR SRSSerializer - could not read number of columns&lt;BR /&gt;
12-03-2018 14:53:28.701 WARN SRSSerializer - could not read schema&lt;BR /&gt;
12-03-2018 14:53:28.723 INFO TimelineCreator - Commit timeline at cursor=1543804147.000000&lt;BR /&gt;
12-03-2018 14:53:28.724 INFO ReducePhaseExecutor - ReducePhaseExecutor=1 action=PREVIEW&lt;BR /&gt;
12-03-2018 14:53:29.073 ERROR SRSSerializer - could not read number of columns&lt;BR /&gt;
12-03-2018 14:53:29.073 WARN SRSSerializer - could not read schema&lt;BR /&gt;
12-03-2018 14:53:29.095 INFO TimelineCreator - Commit timeline at cursor=1543803804.000000&lt;BR /&gt;
12-03-2018 14:53:29.096 INFO ReducePhaseExecutor - ReducePhaseExecutor=1 action=PREVIEW&lt;BR /&gt;
12-03-2018 14:53:29.601 ERROR SRSSerializer - could not read number of columns&lt;BR /&gt;
12-03-2018 14:53:29.601 WARN SRSSerializer - could not read schema&lt;/P&gt;

&lt;P&gt;Due to this error, I cannot search any event which is indexed by the problematic node.&lt;BR /&gt;
Can you please advice how I should proceed further to fix this issue?&lt;/P&gt;

&lt;P&gt;Thank you for your time in advance.&lt;BR /&gt;
Regards,&lt;BR /&gt;
Anh&lt;/P&gt;</description>
      <pubDate>Mon, 03 Dec 2018 08:15:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Search-process-did-not-exit-cleanly-exit-code-255-description/m-p/421003#M6643</guid>
      <dc:creator>lybinhlap</dc:creator>
      <dc:date>2018-12-03T08:15:10Z</dc:date>
    </item>
    <item>
      <title>Re: Search process did not exit cleanly, exit_code=255, description="exited with code 255</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Search-process-did-not-exit-cleanly-exit-code-255-description/m-p/421004#M6644</link>
      <description>&lt;P&gt;&lt;CODE&gt;exit_code = 255&lt;/CODE&gt; was about no disk space left, in our case, at &lt;A href="https://answers.splunk.com/answers/587991/why-do-we-get-the-exited-with-code-255-errors.html"&gt;Why do we get the exited with code 255 errors?&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Dec 2018 15:29:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Search-process-did-not-exit-cleanly-exit-code-255-description/m-p/421004#M6644</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2018-12-03T15:29:49Z</dc:date>
    </item>
    <item>
      <title>Re: Search process did not exit cleanly, exit_code=255, description="exited with code 255</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Search-process-did-not-exit-cleanly-exit-code-255-description/m-p/421005#M6645</link>
      <description>&lt;P&gt;the system is having nearly 1 TB free space. So I dont think this related to space on system.&lt;BR /&gt;
Furthermore, I saw the following error on search.log:&lt;BR /&gt;
12-03-2018 14:53:29.073 ERROR SRSSerializer - could not read number of columns&lt;BR /&gt;
12-03-2018 14:53:29.073 WARN SRSSerializer - could not read schema&lt;/P&gt;

&lt;P&gt;Is there anyone know what this error mean?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2018 07:43:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Search-process-did-not-exit-cleanly-exit-code-255-description/m-p/421005#M6645</guid>
      <dc:creator>anhhoangduc</dc:creator>
      <dc:date>2018-12-04T07:43:44Z</dc:date>
    </item>
  </channel>
</rss>

