<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Error message when creating a diag file in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Error-message-when-creating-a-diag-file/m-p/350772#M166030</link>
    <description>&lt;P&gt;Hello All,&lt;/P&gt;

&lt;P&gt;I'm receiving the following error when I try to create a diag file;&lt;/P&gt;

&lt;P&gt;./splunk diag&lt;BR /&gt;
Collecting components: app:splunk_app_db_connect, conf_replication_summary, consensus, dispatch, etc, file_validate, index_files, index_listing, kvstore, log, pool, searchpeers&lt;BR /&gt;
Skipping components: rest&lt;BR /&gt;
Selected diag name of: diag-pel501.mascocs.com-2017-09-19_12-51-02&lt;BR /&gt;
Starting splunk diag...&lt;BR /&gt;
Logged search filtering is enabled.&lt;BR /&gt;
Skipping REST endpoint gathering...&lt;BR /&gt;
Determining diag-launching user...&lt;BR /&gt;
Getting version info...&lt;BR /&gt;
Getting system version info...&lt;BR /&gt;
Getting file integrity info...&lt;BR /&gt;
Getting network interface config info...&lt;BR /&gt;
Getting splunk processes info...&lt;BR /&gt;
Getting netstat output...&lt;BR /&gt;
Getting info about memory, ulimits, cpu (on windows this takes a while)...&lt;BR /&gt;
Getting etc/auth filenames...&lt;BR /&gt;
Getting Sinkhole filenames...&lt;BR /&gt;
Getting search peer bundles listings...&lt;BR /&gt;
Getting conf replication summary listings...&lt;BR /&gt;
Getting KV Store listings...&lt;BR /&gt;
Getting index listings...&lt;BR /&gt;
Copying Splunk configuration files...&lt;BR /&gt;
filtered out file '/opt/splunk/etc/apps/SA-VMW-HierarchyInventory/lookups/TimeVirtualMachinesOnDatastore.csv'  limit: 10485760  size: 11582385&lt;BR /&gt;
filtered out file '/opt/splunk/etc/apps/SA-EndpointProtection/lookups/localprocesses_tracker.csv'  limit: 10485760  size: 1261901947&lt;BR /&gt;
Exception occurred while generating diag, we are deeply sorry.&lt;BR /&gt;
Traceback (most recent call last):&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/info_gather.py", line 4573, in main&lt;BR /&gt;
    create_diag(options, log_buffer)&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/info_gather.py", line 4096, in create_diag&lt;BR /&gt;
    copy_etc(options)&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/info_gather.py", line 1939, in copy_etc&lt;BR /&gt;
    add_dir_to_diag(etc_dir, "etc", ignore=etc_filt)&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/info_gather.py", line 693, in add_dir_to_diag&lt;BR /&gt;
    storage.add_dir(dir_path, diag_path, ignore=ignore)&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/info_gather.py", line 488, in add_dir&lt;BR /&gt;
    collect_tree(dir_path, diag_path, adder, ignore=ignore)&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/info_gather.py", line 3069, in collect_tree&lt;BR /&gt;
    collect_tree(srcname, dstname, actor, ignore)&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/info_gather.py", line 3069, in collect_tree&lt;BR /&gt;
    collect_tree(srcname, dstname, actor, ignore)&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/info_gather.py", line 3069, in collect_tree&lt;BR /&gt;
    collect_tree(srcname, dstname, actor, ignore)&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/info_gather.py", line 3072, in collect_tree&lt;BR /&gt;
    actor(srcname, dstname)&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/info_gather.py", line 649, in add_file_to_diag&lt;BR /&gt;
    add_fake_special_file_to_diag(file_path, diag_path, special_type)&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/info_gather.py", line 625, in add_fake_special_file_to_diag&lt;BR /&gt;
    storage.add_fake_file(file_path, name)&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/info_gather.py", line 506, in add_fake_file&lt;BR /&gt;
    tinfo.size = 0&lt;BR /&gt;
AttributeError: 'NoneType' object has no attribute 'size'&lt;/P&gt;

&lt;P&gt;Diag failure, writing out logged messages to '/tmp/diag-fail-TUZmYc.txt', please send output + this file to either an existing or new case ; &lt;A href="http://www.splunk.com/support" target="_blank"&gt;http://www.splunk.com/support&lt;/A&gt;&lt;BR /&gt;
We will now try to clean out any temporary files...&lt;/P&gt;

&lt;P&gt;Has anyone seen this error before?&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 15:53:10 GMT</pubDate>
    <dc:creator>jrsanders</dc:creator>
    <dc:date>2020-09-29T15:53:10Z</dc:date>
    <item>
      <title>Error message when creating a diag file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Error-message-when-creating-a-diag-file/m-p/350772#M166030</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;

&lt;P&gt;I'm receiving the following error when I try to create a diag file;&lt;/P&gt;

&lt;P&gt;./splunk diag&lt;BR /&gt;
Collecting components: app:splunk_app_db_connect, conf_replication_summary, consensus, dispatch, etc, file_validate, index_files, index_listing, kvstore, log, pool, searchpeers&lt;BR /&gt;
Skipping components: rest&lt;BR /&gt;
Selected diag name of: diag-pel501.mascocs.com-2017-09-19_12-51-02&lt;BR /&gt;
Starting splunk diag...&lt;BR /&gt;
Logged search filtering is enabled.&lt;BR /&gt;
Skipping REST endpoint gathering...&lt;BR /&gt;
Determining diag-launching user...&lt;BR /&gt;
Getting version info...&lt;BR /&gt;
Getting system version info...&lt;BR /&gt;
Getting file integrity info...&lt;BR /&gt;
Getting network interface config info...&lt;BR /&gt;
Getting splunk processes info...&lt;BR /&gt;
Getting netstat output...&lt;BR /&gt;
Getting info about memory, ulimits, cpu (on windows this takes a while)...&lt;BR /&gt;
Getting etc/auth filenames...&lt;BR /&gt;
Getting Sinkhole filenames...&lt;BR /&gt;
Getting search peer bundles listings...&lt;BR /&gt;
Getting conf replication summary listings...&lt;BR /&gt;
Getting KV Store listings...&lt;BR /&gt;
Getting index listings...&lt;BR /&gt;
Copying Splunk configuration files...&lt;BR /&gt;
filtered out file '/opt/splunk/etc/apps/SA-VMW-HierarchyInventory/lookups/TimeVirtualMachinesOnDatastore.csv'  limit: 10485760  size: 11582385&lt;BR /&gt;
filtered out file '/opt/splunk/etc/apps/SA-EndpointProtection/lookups/localprocesses_tracker.csv'  limit: 10485760  size: 1261901947&lt;BR /&gt;
Exception occurred while generating diag, we are deeply sorry.&lt;BR /&gt;
Traceback (most recent call last):&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/info_gather.py", line 4573, in main&lt;BR /&gt;
    create_diag(options, log_buffer)&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/info_gather.py", line 4096, in create_diag&lt;BR /&gt;
    copy_etc(options)&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/info_gather.py", line 1939, in copy_etc&lt;BR /&gt;
    add_dir_to_diag(etc_dir, "etc", ignore=etc_filt)&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/info_gather.py", line 693, in add_dir_to_diag&lt;BR /&gt;
    storage.add_dir(dir_path, diag_path, ignore=ignore)&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/info_gather.py", line 488, in add_dir&lt;BR /&gt;
    collect_tree(dir_path, diag_path, adder, ignore=ignore)&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/info_gather.py", line 3069, in collect_tree&lt;BR /&gt;
    collect_tree(srcname, dstname, actor, ignore)&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/info_gather.py", line 3069, in collect_tree&lt;BR /&gt;
    collect_tree(srcname, dstname, actor, ignore)&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/info_gather.py", line 3069, in collect_tree&lt;BR /&gt;
    collect_tree(srcname, dstname, actor, ignore)&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/info_gather.py", line 3072, in collect_tree&lt;BR /&gt;
    actor(srcname, dstname)&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/info_gather.py", line 649, in add_file_to_diag&lt;BR /&gt;
    add_fake_special_file_to_diag(file_path, diag_path, special_type)&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/info_gather.py", line 625, in add_fake_special_file_to_diag&lt;BR /&gt;
    storage.add_fake_file(file_path, name)&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/site-packages/splunk/clilib/info_gather.py", line 506, in add_fake_file&lt;BR /&gt;
    tinfo.size = 0&lt;BR /&gt;
AttributeError: 'NoneType' object has no attribute 'size'&lt;/P&gt;

&lt;P&gt;Diag failure, writing out logged messages to '/tmp/diag-fail-TUZmYc.txt', please send output + this file to either an existing or new case ; &lt;A href="http://www.splunk.com/support" target="_blank"&gt;http://www.splunk.com/support&lt;/A&gt;&lt;BR /&gt;
We will now try to clean out any temporary files...&lt;/P&gt;

&lt;P&gt;Has anyone seen this error before?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:53:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Error-message-when-creating-a-diag-file/m-p/350772#M166030</guid>
      <dc:creator>jrsanders</dc:creator>
      <dc:date>2020-09-29T15:53:10Z</dc:date>
    </item>
    <item>
      <title>Re: Error message when creating a diag file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Error-message-when-creating-a-diag-file/m-p/350773#M166031</link>
      <description>&lt;P&gt;Have you tried running a diag without the etc directory. This should help narrow down where the pythons script is having issues. Typically users have binaries files in the etc directory that will cause issues.&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;$SPLUNK_HOME/bin/splunk diag --disable=etc&lt;/EM&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2017 17:58:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Error-message-when-creating-a-diag-file/m-p/350773#M166031</guid>
      <dc:creator>nmurillo_splunk</dc:creator>
      <dc:date>2017-10-03T17:58:54Z</dc:date>
    </item>
    <item>
      <title>Re: Error message when creating a diag file</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Error-message-when-creating-a-diag-file/m-p/350774#M166032</link>
      <description>&lt;P&gt;Try running the below python script directly for diag.&lt;/P&gt;

&lt;P&gt;./splunk cmd python $SPLUNK_HOME/lib/python2.7/site-packages/splunk/clilib/info_gather.py&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 05:37:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Error-message-when-creating-a-diag-file/m-p/350774#M166032</guid>
      <dc:creator>saravanan90</dc:creator>
      <dc:date>2020-09-30T05:37:12Z</dc:date>
    </item>
  </channel>
</rss>

