<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help me understand the error logs. in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Help-me-understand-the-error-logs/m-p/748297#M10951</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/309571"&gt;@KishoreSrini&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Can you check if there is any permission issue?&amp;nbsp;&lt;/P&gt;&lt;P&gt;collectd: processmon plugin: Error reading /proc/3605381/stat&lt;BR /&gt;collectd failed to read process stats, likely because the process with PID 3605381 ended or permissions were insufficient&lt;/P&gt;&lt;P&gt;"/opt/splunkforwarder/var/log/splunk/splunkd.log": No such file or directory - Splunk couldn't access it's main splunkd.log file this also indicates about file unavailablity or permission issue&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Prewin&lt;BR /&gt;Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!&lt;/P&gt;</description>
    <pubDate>Thu, 19 Jun 2025 07:45:07 GMT</pubDate>
    <dc:creator>PrewinThomas</dc:creator>
    <dc:date>2025-06-19T07:45:07Z</dc:date>
    <item>
      <title>Help me understand the error logs.</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Help-me-understand-the-error-logs/m-p/748295#M10950</link>
      <description>&lt;P&gt;I am newbie to this env and I'm trying to understand some logs regrading a linux server troubleshoot. A server stopped sending metrics to Splunk (eventlogs are fine). To troubleshoot, I searched the error logs on that time stamp. These are the logs I got,&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;15:02:44.000:&amp;nbsp;&lt;/SPAN&gt;collectd&lt;/SPAN&gt;&lt;SPAN&gt;[&lt;/SPAN&gt;&lt;SPAN class=""&gt;909&lt;/SPAN&gt;&lt;SPAN&gt;]&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt; &lt;SPAN class=""&gt;processmon&lt;/SPAN&gt; &lt;SPAN class=""&gt;plugin:&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Error&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;reading&lt;/SPAN&gt; &lt;SPAN class=""&gt;/proc/3605381/stat&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;15:12:53.000:&amp;nbsp;&lt;/SPAN&gt;runsvc.sh&lt;SPAN&gt;[&lt;/SPAN&gt;968&lt;SPAN&gt;]&lt;/SPAN&gt;: &lt;SPAN class=""&gt;Error&lt;/SPAN&gt; reported in diagnostic logs. Please examine the log for more details.&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;15:12:53.000:&amp;nbsp;&lt;/SPAN&gt;runsvc.sh&lt;SPAN&gt;[&lt;/SPAN&gt;968&lt;SPAN&gt;]&lt;/SPAN&gt;: 2025-06-13 19:12:53Z: Agent connect &lt;SPAN class=""&gt;error&lt;/SPAN&gt;: The HTTP request timed out after 00:01:00.. Retrying until reconnected.&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;15:31:07.000:&amp;nbsp;&lt;/SPAN&gt;splunk&lt;/SPAN&gt;&lt;SPAN&gt;[&lt;/SPAN&gt;3844643&lt;SPAN&gt;]&lt;/SPAN&gt;: &lt;SPAN class=""&gt;ERROR&lt;/SPAN&gt; - Failed opening&lt;SPAN&gt; "&lt;/SPAN&gt;/opt/splunkforwarder/var/log/splunk/splunkd.log&lt;SPAN&gt;"&lt;/SPAN&gt;: No such file or directory&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;Please help to understand the issue and troubleshooting steps for the issue(If possible)&lt;BR /&gt;&lt;BR /&gt;Thank you in advance.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jun 2025 07:01:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Help-me-understand-the-error-logs/m-p/748295#M10950</guid>
      <dc:creator>KishoreSrini</dc:creator>
      <dc:date>2025-06-19T07:01:51Z</dc:date>
    </item>
    <item>
      <title>Re: Help me understand the error logs.</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Help-me-understand-the-error-logs/m-p/748297#M10951</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/309571"&gt;@KishoreSrini&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Can you check if there is any permission issue?&amp;nbsp;&lt;/P&gt;&lt;P&gt;collectd: processmon plugin: Error reading /proc/3605381/stat&lt;BR /&gt;collectd failed to read process stats, likely because the process with PID 3605381 ended or permissions were insufficient&lt;/P&gt;&lt;P&gt;"/opt/splunkforwarder/var/log/splunk/splunkd.log": No such file or directory - Splunk couldn't access it's main splunkd.log file this also indicates about file unavailablity or permission issue&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Prewin&lt;BR /&gt;Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jun 2025 07:45:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Help-me-understand-the-error-logs/m-p/748297#M10951</guid>
      <dc:creator>PrewinThomas</dc:creator>
      <dc:date>2025-06-19T07:45:07Z</dc:date>
    </item>
    <item>
      <title>Re: Help me understand the error logs.</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Help-me-understand-the-error-logs/m-p/748299#M10952</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/309571"&gt;@KishoreSrini&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think the collectd and runsvc.sh logs are not Splunk related, these look like they might be associated with&amp;nbsp;&lt;SPAN&gt;VstsAgentService - Is this a VM running on Azure / Azure Pipelines?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regarding the Splunk error failed to open file - Can you confirm if the file actually exists in the filesystem? And if so, what events are in the splunkd.log? Are there any warnings/errors?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Please could you confirm the ownership on /opt/splunkforwarder/var/log/splunk/splunkd.log and also confirm the user which Splunk is running as:&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;ps -a | grep -i splunk&lt;/LI-CODE&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jun 2025 07:56:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Help-me-understand-the-error-logs/m-p/748299#M10952</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-06-19T07:56:41Z</dc:date>
    </item>
    <item>
      <title>Re: Help me understand the error logs.</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Help-me-understand-the-error-logs/m-p/748306#M10953</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;/&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/28010"&gt;@PrewinThomas&lt;/a&gt;&amp;nbsp;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;Yes, The linux server is a VM running on azure.&amp;nbsp;I am checking the access and availability of the file as mentioned. Will let you know once I'm done.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;The Splunkd event,&lt;BR /&gt;&lt;SPAN class=""&gt;06-13-2025&lt;/SPAN&gt; &lt;SPAN class=""&gt;19:30:53.923&lt;/SPAN&gt;&lt;SPAN&gt; +&lt;/SPAN&gt;&lt;SPAN class=""&gt;0000&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;ERROR&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;AggregatorMiningProcessor&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class=""&gt;3844932&lt;/SPAN&gt; &lt;SPAN class=""&gt;structuredparsing&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;Uncaught&lt;/SPAN&gt; &lt;SPAN class=""&gt;exception&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;Aggregator&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;skipping&lt;/SPAN&gt; &lt;SPAN class=""&gt;an&lt;/SPAN&gt; &lt;SPAN class=""&gt;event:&lt;/SPAN&gt; &lt;SPAN class=""&gt;Can&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class=""&gt;t&lt;/SPAN&gt; &lt;SPAN class=""&gt;open&lt;/SPAN&gt; &lt;SPAN class=""&gt;DateParser&lt;/SPAN&gt; &lt;SPAN class=""&gt;XML&lt;/SPAN&gt; &lt;SPAN class=""&gt;configuration&lt;/SPAN&gt; &lt;SPAN class=""&gt;file&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;/opt/splunkforwarder/etc/datetime.xml&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt; &lt;SPAN class=""&gt;No&lt;/SPAN&gt; &lt;SPAN class=""&gt;such&lt;/SPAN&gt; &lt;SPAN class=""&gt;file&lt;/SPAN&gt; &lt;SPAN class=""&gt;or&lt;/SPAN&gt; &lt;SPAN class=""&gt;directory&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;data_source=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;/opt/splunkforwarder/var/spool/splunk/tracker.log&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;data_host=&lt;/SPAN&gt;&lt;SPAN&gt;"-----&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN class=""&gt;data_sourcetype=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;splunkd_latency_tracker"&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;06-13-2025&lt;/SPAN&gt; &lt;SPAN class=""&gt;19:28:30.171&lt;/SPAN&gt;&lt;SPAN&gt; +&lt;/SPAN&gt;&lt;SPAN class=""&gt;0000&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;ERROR&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;ExecProcessor&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class=""&gt;3844925&lt;/SPAN&gt; &lt;SPAN class=""&gt;ExecProcessor&lt;/SPAN&gt;&lt;SPAN&gt;] &lt;/SPAN&gt;&lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;message&lt;/SPAN&gt; &lt;SPAN class=""&gt;from&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;/opt/splunkforwarder/etc/apps/pwc_west_ghs_uf_nix_v2/bin/package.sh&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;/bin/sh:&lt;/SPAN&gt; &lt;SPAN class=""&gt;1:&lt;/SPAN&gt; &lt;SPAN class=""&gt;/opt/splunkforwarder/etc/apps/pwc_west_ghs_uf_nix_v2/bin/package.sh:&lt;/SPAN&gt; &lt;SPAN class=""&gt;not&lt;/SPAN&gt; &lt;SPAN class=""&gt;found&lt;BR /&gt;&lt;BR /&gt;06-13-2025 18:28:29.084&lt;SPAN&gt; +&lt;/SPAN&gt;0000 &lt;SPAN class=""&gt;ERROR&lt;/SPAN&gt; ExecProcessor&lt;SPAN&gt; [&lt;/SPAN&gt;3844925 ExecProcessor&lt;SPAN&gt;] &lt;/SPAN&gt;- message from&lt;SPAN&gt; "&lt;/SPAN&gt;/opt/splunkforwarder/etc/apps/pwc_west_ghs_uf_nix_v2/bin/hardware.sh&lt;SPAN&gt;" &lt;/SPAN&gt;/bin/sh: 1: /opt/splunkforwarder/etc/apps/pwc_west_ghs_uf_nix_v2/bin/hardware.sh: not found&lt;BR /&gt;&lt;BR /&gt;Is possible to narrow down the issue with these events?&lt;BR /&gt;&lt;/SPAN&gt;&lt;BR /&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jun 2025 10:21:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Help-me-understand-the-error-logs/m-p/748306#M10953</guid>
      <dc:creator>KishoreSrini</dc:creator>
      <dc:date>2025-06-19T10:21:45Z</dc:date>
    </item>
    <item>
      <title>Re: Help me understand the error logs.</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Help-me-understand-the-error-logs/m-p/748322#M10954</link>
      <description>&lt;P&gt;Thanks, Im wondering if its a permissions issue. The details on what the process is running as and the ownership of the files in /opt/splunkforwarder should help rule it in/out either way! Let me know if you can get hold of this information.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jun 2025 11:52:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Help-me-understand-the-error-logs/m-p/748322#M10954</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-06-19T11:52:29Z</dc:date>
    </item>
  </channel>
</rss>

