<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk hangs browser doing simple search with ERROR StreamGroup log entry in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-hangs-browser-doing-simple-search-with-ERROR-StreamGroup/m-p/188239#M187089</link>
    <description>&lt;P&gt;I was seeing exactly the error as described by @khyoung, except the name of the hot bucket was different in my case (hot_v1_518 instead of hot_v1_1). I am on splunk 5.0.2 with "Splunk App for unix and linux" version 5.01. (I mention this because the OS db is used by this app). It did not hanging my browser, but I happened to be running a tail -f in the background piping to a grep for ERROR and this started showing up after I had stopped splunk, manually re-installed the app, and restarted splunk. (I had to manually re-install the app because someone here accidentally rm'd something in there.)&lt;/P&gt;

&lt;P&gt;So, I went searching for this error and found your splunk question and comments, and as no one had any answers -- and I had already tried stopping and starting splunk, I decided to try this (WARNING -- &lt;STRONG&gt;stop splunk first!&lt;/STRONG&gt;)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;splunk fsck --repair --index os --all
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;an guess what? After I restarted splunk I did not see this error anymore. See if it works for you.&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 16:36:01 GMT</pubDate>
    <dc:creator>wrangler2x</dc:creator>
    <dc:date>2020-09-28T16:36:01Z</dc:date>
    <item>
      <title>Splunk hangs browser doing simple search with ERROR StreamGroup log entry</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-hangs-browser-doing-simple-search-with-ERROR-StreamGroup/m-p/188235#M187085</link>
      <description>&lt;P&gt;Here is the log entry from splunkd.log:&lt;/P&gt;

&lt;P&gt;12-23-2013 11:47:26.478 -0500 ERROR StreamGroup - Dumping contents of file="/idm/idmt_home/splunk/var/lib/splunk/os/db/hot_v1_228/splunk-autogen-params.dat" txnPerSync=97:&lt;BR /&gt;
12-23-2013 11:47:26.478 -0500 ERROR StreamGroup - SPLUNK AUTO-GENERATED FILE. DO NOT MODIFY.|129554|1844773|1114686|32866|97|&lt;/P&gt;

&lt;P&gt;I've restarted Splunk with no success.  I am on version Splunk 6.0 (build 182037)&lt;/P&gt;

&lt;P&gt;Any suggestions?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:32:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-hangs-browser-doing-simple-search-with-ERROR-StreamGroup/m-p/188235#M187085</guid>
      <dc:creator>working_dog</dc:creator>
      <dc:date>2020-09-28T15:32:07Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk hangs browser doing simple search with ERROR StreamGroup log entry</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-hangs-browser-doing-simple-search-with-ERROR-StreamGroup/m-p/188236#M187086</link>
      <description>&lt;P&gt;Me too....&lt;BR /&gt;
I am on version Splunk 6.0.1 and using *NIX&lt;/P&gt;

&lt;P&gt;01-13-2014 16:08:34.380 +0900 ERROR StreamGroup - SPLUNK AUTO-GENERATED FILE. DO NOT MODIFY.|134044|1554700|1117670|32830|61|&lt;BR /&gt;
01-13-2014 16:08:34.380 +0900 ERROR StreamGroup - &amp;lt;&amp;lt;&amp;lt;EOF file="/opt/sp_test/splunk/var/lib/splunk/os/db/hot_v1_1/splunk-autogen-params.dat"&lt;BR /&gt;
01-13-2014 16:09:04.379 +0900 ERROR StreamGroup - Dumping contents of file="/opt/sp_test/splunk/var/lib/splunk/os/db/hot_v1_1/splunk-autogen-params.dat" txnPerSync=61:&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:38:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-hangs-browser-doing-simple-search-with-ERROR-StreamGroup/m-p/188236#M187086</guid>
      <dc:creator>khyoung7410</dc:creator>
      <dc:date>2020-09-28T15:38:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk hangs browser doing simple search with ERROR StreamGroup log entry</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-hangs-browser-doing-simple-search-with-ERROR-StreamGroup/m-p/188237#M187087</link>
      <description>&lt;P&gt;I'm getting this too, and I can't seem to figure it out. Have you guys had any luck yet?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2014 22:04:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-hangs-browser-doing-simple-search-with-ERROR-StreamGroup/m-p/188237#M187087</guid>
      <dc:creator>bensbrowning</dc:creator>
      <dc:date>2014-02-07T22:04:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk hangs browser doing simple search with ERROR StreamGroup log entry</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-hangs-browser-doing-simple-search-with-ERROR-StreamGroup/m-p/188238#M187088</link>
      <description>&lt;P&gt;Is it possible that there's a single line event written into the logs that is extraordinarily long?   I recently found that single line events with tens of thousands or hundreds of thousands of characters can hang the browser.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2014 22:08:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-hangs-browser-doing-simple-search-with-ERROR-StreamGroup/m-p/188238#M187088</guid>
      <dc:creator>sideview</dc:creator>
      <dc:date>2014-02-07T22:08:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk hangs browser doing simple search with ERROR StreamGroup log entry</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-hangs-browser-doing-simple-search-with-ERROR-StreamGroup/m-p/188239#M187089</link>
      <description>&lt;P&gt;I was seeing exactly the error as described by @khyoung, except the name of the hot bucket was different in my case (hot_v1_518 instead of hot_v1_1). I am on splunk 5.0.2 with "Splunk App for unix and linux" version 5.01. (I mention this because the OS db is used by this app). It did not hanging my browser, but I happened to be running a tail -f in the background piping to a grep for ERROR and this started showing up after I had stopped splunk, manually re-installed the app, and restarted splunk. (I had to manually re-install the app because someone here accidentally rm'd something in there.)&lt;/P&gt;

&lt;P&gt;So, I went searching for this error and found your splunk question and comments, and as no one had any answers -- and I had already tried stopping and starting splunk, I decided to try this (WARNING -- &lt;STRONG&gt;stop splunk first!&lt;/STRONG&gt;)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;splunk fsck --repair --index os --all
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;an guess what? After I restarted splunk I did not see this error anymore. See if it works for you.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:36:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-hangs-browser-doing-simple-search-with-ERROR-StreamGroup/m-p/188239#M187089</guid>
      <dc:creator>wrangler2x</dc:creator>
      <dc:date>2020-09-28T16:36:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk hangs browser doing simple search with ERROR StreamGroup log entry</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-hangs-browser-doing-simple-search-with-ERROR-StreamGroup/m-p/188240#M187090</link>
      <description>&lt;P&gt;Another thing that might be pointer to check out, is if you have any events, not parsed correctly in this data.&lt;/P&gt;

&lt;P&gt;I would check the klpitest index (in this case) for events with a linecount bigger than 1 (or what ever you expect from your events), and check if i have (a few) events with another timestamp or format in the data. (since this looks like an custom input, custom sourcetype(?) )&lt;/P&gt;

&lt;P&gt;At least i found some events that had not been parsed correctly in those indexes reported by this "Stream group" error. &lt;/P&gt;

&lt;P&gt;I did not however find any other errors or warnings regarding, parsing errors or what not in splunkd.log, for those who are wondering ...&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jul 2014 08:36:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-hangs-browser-doing-simple-search-with-ERROR-StreamGroup/m-p/188240#M187090</guid>
      <dc:creator>lmyrefelt</dc:creator>
      <dc:date>2014-07-18T08:36:29Z</dc:date>
    </item>
  </channel>
</rss>

