<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ERROR StreamedSearch File name too long in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/ERROR-StreamedSearch-File-name-too-long/m-p/78675#M941</link>
    <description>&lt;P&gt;Long Path Tool is useful here&lt;/P&gt;</description>
    <pubDate>Wed, 05 Apr 2017 09:45:15 GMT</pubDate>
    <dc:creator>liona1982</dc:creator>
    <dc:date>2017-04-05T09:45:15Z</dc:date>
    <item>
      <title>ERROR StreamedSearch File name too long</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/ERROR-StreamedSearch-File-name-too-long/m-p/78670#M936</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;We are running 4.2.5-113966.&lt;/P&gt;

&lt;P&gt;Scanning splunkd.log, I see we are getting LOTS of errors (~2600 yesterday) of the form (always a pair of errors):&lt;/P&gt;

&lt;P&gt;02-24-2012 08:01:54.076 -0600 ERROR StreamedSearch - preparing to stream search, failed to mkdir /usr2/splunkshare1/splunk-ui/var/run/splunk/dispatch/remote_&amp;lt;&lt;STRONG&gt;name of the other Splunk Search Head&lt;/STRONG&gt;&amp;gt;-splnkcpo_subsearch_subsearch_scheduler_ &lt;EM&gt;nobody&lt;/EM&gt; &lt;EM&gt;SplunkDeploymentMonitor_RE0gc291cmNldHlwZXMgdG9vIGxpdHRsZSBkYXRh_at_1330092000_8faa392bb73975e&lt;BR /&gt;
f_1330092112.2_1330092112.3&lt;/EM&gt;&amp;lt;&lt;STRONG&gt;name of THIS Splunk Search Head&lt;/STRONG&gt;&amp;gt;: File name too long&lt;/P&gt;

&lt;P&gt;02-24-2012 08:01:54.077 -0600 ERROR SearchResults - Unable to open output file: path=/usr2/splunkshare1/splunk-ui/var/run/splunk/dispatch/remote_&amp;lt;&lt;STRONG&gt;name of the other Splunk Search Head&lt;/STRONG&gt;&amp;gt;-splnkcpo_subsearch_subsearch_scheduler_ &lt;EM&gt;nobody&lt;/EM&gt; &lt;EM&gt;SplunkDeploymentMonitor_RE0gc291cmNldHlwZXMgdG9vIGxpdHRsZSBkYXRh_at_1330092000_8faa392bb73975ef_1330092112&lt;BR /&gt;
.2_1330092112.3&lt;/EM&gt;&amp;lt;&lt;STRONG&gt;name of THIS Splunk Search Head&lt;/STRONG&gt;&amp;gt;-splnkcpo/info.csv.tmp error=File name too long&lt;/P&gt;

&lt;P&gt;It would seem that there is some mechanism / algorithm that is generating these long file names -- longer than Linux can handle.&lt;/P&gt;

&lt;P&gt;Any ideas??&lt;/P&gt;

&lt;P&gt;Thx!&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:26:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/ERROR-StreamedSearch-File-name-too-long/m-p/78670#M936</guid>
      <dc:creator>mfeeny1</dc:creator>
      <dc:date>2020-09-28T11:26:33Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR StreamedSearch File name too long</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/ERROR-StreamedSearch-File-name-too-long/m-p/78671#M937</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;It smells like a http restriction, instead of OS filesystem restriction. Splunk use REST API to communicate with splunkd (default 8089/tcp). &lt;/P&gt;

&lt;P&gt;The dispatch sid name is a little strange;&lt;/P&gt;

&lt;P&gt;But, this should not happen in 4.2.5 because the sid of dispatched search should not use &lt;B&gt;&amp;lt;name of THIS Splunk Search Head&amp;gt;-splunkcpo&lt;/B&gt;&lt;/P&gt;

&lt;P&gt;Are you using  the same version 4.2.5 for both Splunk instance? &lt;/P&gt;

&lt;P&gt;Maybe you should file a Support case to ask to investigate more about the issue.&lt;/P&gt;</description>
      <pubDate>Sun, 26 Feb 2012 05:17:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/ERROR-StreamedSearch-File-name-too-long/m-p/78671#M937</guid>
      <dc:creator>Masa</dc:creator>
      <dc:date>2012-02-26T05:17:25Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR StreamedSearch File name too long</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/ERROR-StreamedSearch-File-name-too-long/m-p/78672#M938</link>
      <description>&lt;P&gt;Long Path Tool helped me in this situation. &lt;A href="http://PathTooDeep.com"&gt;http://PathTooDeep.com&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 23 Sep 2012 21:27:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/ERROR-StreamedSearch-File-name-too-long/m-p/78672#M938</guid>
      <dc:creator>DannyLoff</dc:creator>
      <dc:date>2012-09-23T21:27:18Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR StreamedSearch File name too long</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/ERROR-StreamedSearch-File-name-too-long/m-p/78673#M939</link>
      <description>&lt;P&gt;Long Path Tool helped me in this situation. &lt;A href="http://PathTooDeep.com"&gt;http://PathTooDeep.com&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Oct 2012 06:32:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/ERROR-StreamedSearch-File-name-too-long/m-p/78673#M939</guid>
      <dc:creator>Nelson32</dc:creator>
      <dc:date>2012-10-02T06:32:16Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR StreamedSearch File name too long</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/ERROR-StreamedSearch-File-name-too-long/m-p/78674#M940</link>
      <description>&lt;P&gt;You have to checkout long path tool, it's an automated software for this type of errors&lt;/P&gt;</description>
      <pubDate>Fri, 19 Aug 2016 10:05:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/ERROR-StreamedSearch-File-name-too-long/m-p/78674#M940</guid>
      <dc:creator>Ronald87</dc:creator>
      <dc:date>2016-08-19T10:05:54Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR StreamedSearch File name too long</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/ERROR-StreamedSearch-File-name-too-long/m-p/78675#M941</link>
      <description>&lt;P&gt;Long Path Tool is useful here&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2017 09:45:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/ERROR-StreamedSearch-File-name-too-long/m-p/78675#M941</guid>
      <dc:creator>liona1982</dc:creator>
      <dc:date>2017-04-05T09:45:15Z</dc:date>
    </item>
  </channel>
</rss>

