<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Warnings on Splunk TCP Port Closures (Splunk Cloud) in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Warnings-on-Splunk-TCP-Port-Closures-Splunk-Cloud/m-p/448380#M6144</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/184923"&gt;@willemjongeneel&lt;/a&gt;,&lt;/P&gt;

&lt;P&gt;You seems to have two problems there :&lt;/P&gt;

&lt;P&gt;1- The warning message of the subsearch, it seems that the account your using does not have the required capability to run this search. You need to add the dispatch_rest_to_indexers capability.&lt;/P&gt;

&lt;P&gt;2- The error message is trying to reach your distributed search peer configuration but apparently you have nothing configured there locally so the endpoint fails. Make sure to add your search heads as search peers on the monitoring console to be able to fetch data from there.&lt;/P&gt;

&lt;P&gt;Let me know if that helps.&lt;/P&gt;

&lt;P&gt;Cheers,&lt;BR /&gt;
David&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 00:22:34 GMT</pubDate>
    <dc:creator>DavidHourani</dc:creator>
    <dc:date>2020-09-30T00:22:34Z</dc:date>
    <item>
      <title>Warnings on Splunk TCP Port Closures (Splunk Cloud)</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Warnings-on-Splunk-TCP-Port-Closures-Splunk-Cloud/m-p/448379#M6143</link>
      <description>&lt;P&gt;Hello, &lt;/P&gt;

&lt;P&gt;I am receiving warnings on my splunk cloud monitoring console:&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/7022i971FABE372A7F0B8/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;I am not sure what caused this errors to occur. Can anyone tell me what the errors mean and what I can do to resolve them?&lt;/P&gt;

&lt;P&gt;Thanks in advance, kind regards,&lt;/P&gt;

&lt;P&gt;Willem &lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2019 07:49:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Warnings-on-Splunk-TCP-Port-Closures-Splunk-Cloud/m-p/448379#M6143</guid>
      <dc:creator>willemjongeneel</dc:creator>
      <dc:date>2019-05-07T07:49:05Z</dc:date>
    </item>
    <item>
      <title>Re: Warnings on Splunk TCP Port Closures (Splunk Cloud)</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Warnings-on-Splunk-TCP-Port-Closures-Splunk-Cloud/m-p/448380#M6144</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/184923"&gt;@willemjongeneel&lt;/a&gt;,&lt;/P&gt;

&lt;P&gt;You seems to have two problems there :&lt;/P&gt;

&lt;P&gt;1- The warning message of the subsearch, it seems that the account your using does not have the required capability to run this search. You need to add the dispatch_rest_to_indexers capability.&lt;/P&gt;

&lt;P&gt;2- The error message is trying to reach your distributed search peer configuration but apparently you have nothing configured there locally so the endpoint fails. Make sure to add your search heads as search peers on the monitoring console to be able to fetch data from there.&lt;/P&gt;

&lt;P&gt;Let me know if that helps.&lt;/P&gt;

&lt;P&gt;Cheers,&lt;BR /&gt;
David&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:22:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Warnings-on-Splunk-TCP-Port-Closures-Splunk-Cloud/m-p/448380#M6144</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2020-09-30T00:22:34Z</dc:date>
    </item>
    <item>
      <title>Re: Warnings on Splunk TCP Port Closures (Splunk Cloud)</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Warnings-on-Splunk-TCP-Port-Closures-Splunk-Cloud/m-p/448381#M6145</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/68181"&gt;@DavidHourani&lt;/a&gt; &lt;/P&gt;

&lt;P&gt;Thank you for your quick response.&lt;/P&gt;

&lt;P&gt;1: I dont see the dispatch_rest_to_indexers capability in Splunk Cloud GUI. Could it be one of the following capabilities?&lt;/P&gt;

&lt;P&gt;rest_apps_management&lt;BR /&gt;
rest_apps_view&lt;BR /&gt;
rest_properties_get&lt;BR /&gt;
rest_properties_set&lt;/P&gt;

&lt;P&gt;2:  Make sure to add your search heads as search peers on the monitoring console to be able to fetch data from there. --&amp;gt; Do you know if this is possible in managed Splunk Cloud GUI? Where should I add this? &lt;/P&gt;

&lt;P&gt;Kind regards,&lt;BR /&gt;
Willem&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:26:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Warnings-on-Splunk-TCP-Port-Closures-Splunk-Cloud/m-p/448381#M6145</guid>
      <dc:creator>willemjongeneel</dc:creator>
      <dc:date>2020-09-30T00:26:39Z</dc:date>
    </item>
    <item>
      <title>Re: Warnings on Splunk TCP Port Closures (Splunk Cloud)</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Warnings-on-Splunk-TCP-Port-Closures-Splunk-Cloud/m-p/448382#M6146</link>
      <description>&lt;P&gt;Hi @willemjongeneel,&lt;/P&gt;

&lt;P&gt;1: Check here : &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.6/Admin/authorizeconf"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.6/Admin/authorizeconf&lt;/A&gt; the capability is this one : &lt;CODE&gt;[capability::dispatch_rest_to_indexers]&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;2- it should be possible : from settings -&amp;gt; distributed search -&amp;gt; search peers.&lt;BR /&gt;
If you don't have the " distributed search " option then no it's not possible to do it via GUI.&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2019 11:08:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Warnings-on-Splunk-TCP-Port-Closures-Splunk-Cloud/m-p/448382#M6146</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-05-07T11:08:33Z</dc:date>
    </item>
    <item>
      <title>Re: Warnings on Splunk TCP Port Closures (Splunk Cloud)</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Warnings-on-Splunk-TCP-Port-Closures-Splunk-Cloud/m-p/448383#M6147</link>
      <description>&lt;P&gt;Hi @DavidHourani &lt;/P&gt;

&lt;P&gt;I cannot see this capability in Splunk Cloud.&lt;BR /&gt;
Also I dont have the distributed search option in the Splunk Cloud gui. &lt;/P&gt;

&lt;P&gt;I'll make a ticket at Splunk support for this.&lt;/P&gt;

&lt;P&gt;Thanks for your help.&lt;/P&gt;

&lt;P&gt;Kind regards,&lt;BR /&gt;
Willem Jongeneel&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2019 13:06:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Warnings-on-Splunk-TCP-Port-Closures-Splunk-Cloud/m-p/448383#M6147</guid>
      <dc:creator>willemjongeneel</dc:creator>
      <dc:date>2019-05-07T13:06:41Z</dc:date>
    </item>
    <item>
      <title>Re: Warnings on Splunk TCP Port Closures (Splunk Cloud)</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Warnings-on-Splunk-TCP-Port-Closures-Splunk-Cloud/m-p/448384#M6148</link>
      <description>&lt;P&gt;Most welcome! Let me know how that turns up. And please accept the answer if it helped &lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2019 13:25:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Warnings-on-Splunk-TCP-Port-Closures-Splunk-Cloud/m-p/448384#M6148</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-05-07T13:25:53Z</dc:date>
    </item>
    <item>
      <title>Re: Warnings on Splunk TCP Port Closures (Splunk Cloud)</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Warnings-on-Splunk-TCP-Port-Closures-Splunk-Cloud/m-p/448385#M6149</link>
      <description>&lt;P&gt;I've received the following response from support:&lt;/P&gt;

&lt;P&gt;yes - there is currently a defect open in the CMC&lt;BR /&gt;
The "dispatch_rest_to_indexers" capability has been removed from everyone. It was a code change. &lt;/P&gt;

&lt;P&gt;It will be fixed CMC v.1.2 - but no eta as of yet .&lt;/P&gt;

&lt;P&gt;Kind regards,&lt;BR /&gt;
Willem&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:23:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Warnings-on-Splunk-TCP-Port-Closures-Splunk-Cloud/m-p/448385#M6149</guid>
      <dc:creator>willemjongeneel</dc:creator>
      <dc:date>2020-09-30T00:23:03Z</dc:date>
    </item>
    <item>
      <title>Re: Warnings on Splunk TCP Port Closures (Splunk Cloud)</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Warnings-on-Splunk-TCP-Port-Closures-Splunk-Cloud/m-p/548969#M6150</link>
      <description>&lt;P&gt;Thanks for that. It's April 2021 and no fix for this, yet.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 13:53:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Warnings-on-Splunk-TCP-Port-Closures-Splunk-Cloud/m-p/548969#M6150</guid>
      <dc:creator>dougtc</dc:creator>
      <dc:date>2021-04-22T13:53:36Z</dc:date>
    </item>
  </channel>
</rss>

