<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Error Spamming Splunkd.log Error Process_Search in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Error-Spamming-Splunkd-log-Error-Process-Search/m-p/164314#M1820</link>
    <description>&lt;P&gt;Somehow the directories (and all the child directories/files) of "var/run" and "var/spool" lost all permissions. Giving Permissions to System/Administrator of the folders and their child folders may have fixed my issue.&lt;/P&gt;

&lt;P&gt;Edit:&lt;BR /&gt;
It appears that all of these files are being created automatically with no permissions, When splunk tries to read them it can't find them. This appears to be a bug in Splunk and is happening on my own machine and my Dev Machine.&lt;/P&gt;</description>
    <pubDate>Thu, 05 Dec 2013 15:31:01 GMT</pubDate>
    <dc:creator>aelliott</dc:creator>
    <dc:date>2013-12-05T15:31:01Z</dc:date>
    <item>
      <title>Error Spamming Splunkd.log Error Process_Search</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Error-Spamming-Splunkd-log-Error-Process-Search/m-p/164312#M1818</link>
      <description>&lt;P&gt;I'm getting the following spammed hundreds of thousands of time in my log splunkd.log file&lt;/P&gt;

&lt;P&gt;ERROR ProcessDispatchedSearch - PROCESS_SEARCH - Error opening C:\Program Files\Splunk\var\run\splunk\dispatch\{insertDirectoryNameHere}\search.log: The operation completed successfully.&lt;/P&gt;

&lt;P&gt;This is causing my indexer to become congested and frozen.&lt;BR /&gt;
Attempts to restart splunk fail and when running 'splunk restart' on the server says that port 8090 is in use and it will not allow me to start splunk back up.&lt;/P&gt;

&lt;P&gt;Restarting the machine brings the indexes back to life however this does not last long when using splunk and looking at dashboards etc.&lt;/P&gt;

&lt;P&gt;Splunk is running on a VM with Windows server 2008 R2&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2013 17:47:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Error-Spamming-Splunkd-log-Error-Process-Search/m-p/164312#M1818</guid>
      <dc:creator>aelliott</dc:creator>
      <dc:date>2013-12-03T17:47:58Z</dc:date>
    </item>
    <item>
      <title>Re: Error Spamming Splunkd.log Error Process_Search</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Error-Spamming-Splunkd-log-Error-Process-Search/m-p/164313#M1819</link>
      <description>&lt;P&gt;If you're running anti-virus, that might be causing it.  To get "The operation completed successfully" when opening a file suggests some strange condition that "shouldn't happen", exactly the sort of thing that AV scanners like to cause.  They also love to lock files at inopportune times, which can cause open's to fail.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2013 08:56:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Error-Spamming-Splunkd-log-Error-Process-Search/m-p/164313#M1819</guid>
      <dc:creator>sciurus</dc:creator>
      <dc:date>2013-12-05T08:56:01Z</dc:date>
    </item>
    <item>
      <title>Re: Error Spamming Splunkd.log Error Process_Search</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Error-Spamming-Splunkd-log-Error-Process-Search/m-p/164314#M1820</link>
      <description>&lt;P&gt;Somehow the directories (and all the child directories/files) of "var/run" and "var/spool" lost all permissions. Giving Permissions to System/Administrator of the folders and their child folders may have fixed my issue.&lt;/P&gt;

&lt;P&gt;Edit:&lt;BR /&gt;
It appears that all of these files are being created automatically with no permissions, When splunk tries to read them it can't find them. This appears to be a bug in Splunk and is happening on my own machine and my Dev Machine.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2013 15:31:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Error-Spamming-Splunkd-log-Error-Process-Search/m-p/164314#M1820</guid>
      <dc:creator>aelliott</dc:creator>
      <dc:date>2013-12-05T15:31:01Z</dc:date>
    </item>
    <item>
      <title>Re: Error Spamming Splunkd.log Error Process_Search</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Error-Spamming-Splunkd-log-Error-Process-Search/m-p/164315#M1821</link>
      <description>&lt;P&gt;I believe you are correct, our antivirus is locking many splunk files causing splunk to not work correctly. Since I'm pretty sure this is the issue I am going to mark this as answer, Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2013 15:22:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Error-Spamming-Splunkd-log-Error-Process-Search/m-p/164315#M1821</guid>
      <dc:creator>aelliott</dc:creator>
      <dc:date>2013-12-06T15:22:15Z</dc:date>
    </item>
  </channel>
</rss>

