<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: [indexer] Streamed search execute failed because: User 'nobody' could not act as: in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/indexer-Streamed-search-execute-failed-because-User-nobody-could/m-p/186065#M187016</link>
    <description>&lt;P&gt;I'm having this same message running 6.0.1&lt;/P&gt;

&lt;P&gt;[Messaging Indexer] Streamed search execute failed because: User 'nobody' could not act as:&lt;/P&gt;

&lt;P&gt;2 Search Heads doing search head pooling, 3 Indexers Clustered and I'm getting this prompt for only 1 of my indexers.&lt;/P&gt;

&lt;P&gt;Any thoughts on if this could be a symptomatic message due to other issues with that indexer?  Hardware, I/O constraints accessing indexed data? For me the issue only pops up after some time. &lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Fri, 11 Apr 2014 19:01:13 GMT</pubDate>
    <dc:creator>ctripod</dc:creator>
    <dc:date>2014-04-11T19:01:13Z</dc:date>
    <item>
      <title>[indexer] Streamed search execute failed because: User 'nobody' could not act as:</title>
      <link>https://community.splunk.com/t5/Splunk-Search/indexer-Streamed-search-execute-failed-because-User-nobody-could/m-p/186061#M187012</link>
      <description>&lt;P&gt;Can someone please tell me what this means, and where I can look to fix this?  Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2013 21:11:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/indexer-Streamed-search-execute-failed-because-User-nobody-could/m-p/186061#M187012</guid>
      <dc:creator>x9079</dc:creator>
      <dc:date>2013-12-19T21:11:55Z</dc:date>
    </item>
    <item>
      <title>Re: [indexer] Streamed search execute failed because: User 'nobody' could not act as:</title>
      <link>https://community.splunk.com/t5/Splunk-Search/indexer-Streamed-search-execute-failed-because-User-nobody-could/m-p/186062#M187013</link>
      <description>&lt;P&gt;I too am looking for the solution to this, and have already logged couple of tickets with Splunk support.&lt;/P&gt;

&lt;P&gt;I have just  got confirmation that it is fixed in 6.0.1. &lt;/P&gt;

&lt;P&gt;Going to upgrade now.&lt;/P&gt;

&lt;P&gt;BUT, if you cannot upgrade, as a work around please add below mentioned lines in your search head &lt;/P&gt;

&lt;P&gt;/opt/splunk/etc/system/local/distsearch.conf&lt;/P&gt;

&lt;P&gt;[replicationSettings]&lt;BR /&gt;
&lt;BR /&gt;allowDeltaUpload = false &lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2014 03:57:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/indexer-Streamed-search-execute-failed-because-User-nobody-could/m-p/186062#M187013</guid>
      <dc:creator>saad_siddiqi</dc:creator>
      <dc:date>2014-01-07T03:57:05Z</dc:date>
    </item>
    <item>
      <title>Re: [indexer] Streamed search execute failed because: User 'nobody' could not act as:</title>
      <link>https://community.splunk.com/t5/Splunk-Search/indexer-Streamed-search-execute-failed-because-User-nobody-could/m-p/186063#M187014</link>
      <description>&lt;P&gt;This is fixed in 5.0.6 and 6.0.1 (not 6.0.0 obviously). &lt;/P&gt;

&lt;P&gt;The distsearch.conf is a workaround to disable the whole feature.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Feb 2014 22:28:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/indexer-Streamed-search-execute-failed-because-User-nobody-could/m-p/186063#M187014</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2014-02-18T22:28:22Z</dc:date>
    </item>
    <item>
      <title>Re: [indexer] Streamed search execute failed because: User 'nobody' could not act as:</title>
      <link>https://community.splunk.com/t5/Splunk-Search/indexer-Streamed-search-execute-failed-because-User-nobody-could/m-p/186064#M187015</link>
      <description>&lt;P&gt;I am using 6.0.2.&lt;BR /&gt;
We have 3 Search Heads and 4 Indexers with Search head pooling and mounted bundles.&lt;BR /&gt;
I'm getting the same error.&lt;/P&gt;

&lt;P&gt;Any idea on this?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2014 08:46:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/indexer-Streamed-search-execute-failed-because-User-nobody-could/m-p/186064#M187015</guid>
      <dc:creator>premg</dc:creator>
      <dc:date>2014-04-03T08:46:36Z</dc:date>
    </item>
    <item>
      <title>Re: [indexer] Streamed search execute failed because: User 'nobody' could not act as:</title>
      <link>https://community.splunk.com/t5/Splunk-Search/indexer-Streamed-search-execute-failed-because-User-nobody-could/m-p/186065#M187016</link>
      <description>&lt;P&gt;I'm having this same message running 6.0.1&lt;/P&gt;

&lt;P&gt;[Messaging Indexer] Streamed search execute failed because: User 'nobody' could not act as:&lt;/P&gt;

&lt;P&gt;2 Search Heads doing search head pooling, 3 Indexers Clustered and I'm getting this prompt for only 1 of my indexers.&lt;/P&gt;

&lt;P&gt;Any thoughts on if this could be a symptomatic message due to other issues with that indexer?  Hardware, I/O constraints accessing indexed data? For me the issue only pops up after some time. &lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2014 19:01:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/indexer-Streamed-search-execute-failed-because-User-nobody-could/m-p/186065#M187016</guid>
      <dc:creator>ctripod</dc:creator>
      <dc:date>2014-04-11T19:01:13Z</dc:date>
    </item>
    <item>
      <title>Re: [indexer] Streamed search execute failed because: User 'nobody' could not act as:</title>
      <link>https://community.splunk.com/t5/Splunk-Search/indexer-Streamed-search-execute-failed-because-User-nobody-could/m-p/186066#M187017</link>
      <description>&lt;P&gt;Had this on one search head and one of the indexers attached on 6.0.2.&lt;/P&gt;

&lt;P&gt;Solution:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Remove the indexer from distributed search&lt;/LI&gt;
&lt;LI&gt;Go to $SPLUNK_HOME/var/run/searchpeers and delete all bundle artifacts for the search head in question&lt;/LI&gt;
&lt;LI&gt;Re-attach the indexer to the search head.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 17 Apr 2014 12:18:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/indexer-Streamed-search-execute-failed-because-User-nobody-could/m-p/186066#M187017</guid>
      <dc:creator>my2ndhead</dc:creator>
      <dc:date>2014-04-17T12:18:45Z</dc:date>
    </item>
    <item>
      <title>Re: [indexer] Streamed search execute failed because: User 'nobody' could not act as:</title>
      <link>https://community.splunk.com/t5/Splunk-Search/indexer-Streamed-search-execute-failed-because-User-nobody-could/m-p/186067#M187018</link>
      <description>&lt;P&gt;I tried the solution of deleting the bundles and reattaching the indexer to search head. it worked but the error seem to be happening again. Is there a permanent solution to the problem.&lt;/P&gt;

&lt;P&gt;Poorna&lt;/P&gt;</description>
      <pubDate>Mon, 28 Apr 2014 19:27:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/indexer-Streamed-search-execute-failed-because-User-nobody-could/m-p/186067#M187018</guid>
      <dc:creator>gundepalli</dc:creator>
      <dc:date>2014-04-28T19:27:51Z</dc:date>
    </item>
    <item>
      <title>Re: [indexer] Streamed search execute failed because: User 'nobody' could not act as:</title>
      <link>https://community.splunk.com/t5/Splunk-Search/indexer-Streamed-search-execute-failed-because-User-nobody-could/m-p/186068#M187019</link>
      <description>&lt;P&gt;I am using 6.0.2.2&lt;/P&gt;

&lt;P&gt;I tried this workaround on an ad-hoc search head with multiple indexers and it worked for me.&lt;/P&gt;

&lt;P&gt;I have not tried this on a search head pool, yet.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2014 07:49:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/indexer-Streamed-search-execute-failed-because-User-nobody-could/m-p/186068#M187019</guid>
      <dc:creator>ncsantucci</dc:creator>
      <dc:date>2014-04-30T07:49:43Z</dc:date>
    </item>
    <item>
      <title>Re: [indexer] Streamed search execute failed because: User 'nobody' could not act as:</title>
      <link>https://community.splunk.com/t5/Splunk-Search/indexer-Streamed-search-execute-failed-because-User-nobody-could/m-p/186069#M187020</link>
      <description>&lt;P&gt;I had a similar issue.  Essentially if you happen to use a saved search behind a Dashboard, when you create it the search will be tied to your username.  When this goes to prod, it will still be tied to your username and could count against your user’s limitations for search size, etc, and you might not realize it.  So a best practice is to delete your ownership of the search in the local.meta or default.meta of the app prior to promoting your changes.  You typically only have to do this once after search creation and it will stay owned by “nobody”.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Aug 2014 12:57:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/indexer-Streamed-search-execute-failed-because-User-nobody-could/m-p/186069#M187020</guid>
      <dc:creator>_gkollias</dc:creator>
      <dc:date>2014-08-07T12:57:06Z</dc:date>
    </item>
    <item>
      <title>Re: [indexer] Streamed search execute failed because: User 'nobody' could not act as:</title>
      <link>https://community.splunk.com/t5/Splunk-Search/indexer-Streamed-search-execute-failed-because-User-nobody-could/m-p/186070#M187021</link>
      <description>&lt;P&gt;Thanks, my2ndhead!   &lt;/P&gt;

&lt;P&gt;We had this issue, and this answer led us in the right direction.  We found specific issues between one of our SH and one of our Indexers:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;Determined which SH was causing the issue (e.g. mySearchHead2) and which Indexer from the error message (e.g. myIndexer3)&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Shutdown SH "mySearchHead2"&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Go to the $SPLUNK_HOME/var/run/searchpeers directory on myIndexer3&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;On Indexer, do:   rm -rf mySearchHead2*&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Start SH mySearchHead2 back up&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Problem solved (a whole new bundle will get sent from mySearchHead2 to myIndexer3 and any bad delta's are gone)&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Thu, 07 Aug 2014 14:47:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/indexer-Streamed-search-execute-failed-because-User-nobody-could/m-p/186070#M187021</guid>
      <dc:creator>jhupka</dc:creator>
      <dc:date>2014-08-07T14:47:12Z</dc:date>
    </item>
    <item>
      <title>Re: [indexer] Streamed search execute failed because: User 'nobody' could not act as:</title>
      <link>https://community.splunk.com/t5/Splunk-Search/indexer-Streamed-search-execute-failed-because-User-nobody-could/m-p/186071#M187022</link>
      <description>&lt;P&gt;Making this change in distsearch.conf is the "Big Giant Hammer" solution to this...I suggest trying my2ndhead's steps below since that tries to address just the hiccup that caused this problem. This way you get rid of the bad-stuff that happened to be created instead of hiding the problem behind a setting change. &lt;/P&gt;

&lt;P&gt;If you have big bundles, turning off the delta functionality will cause unnecessary overhead if the root cause was a minor hiccup in the bundle delta replication process.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Aug 2014 14:59:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/indexer-Streamed-search-execute-failed-because-User-nobody-could/m-p/186071#M187022</guid>
      <dc:creator>jhupka</dc:creator>
      <dc:date>2014-08-07T14:59:01Z</dc:date>
    </item>
  </channel>
</rss>

