<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Getting errors for every search I run in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Getting-errors-for-every-search-I-run/m-p/234260#M188485</link>
    <description>&lt;P&gt;Open the job inspector and look in search.log for errors and post any you find there.&lt;/P&gt;

&lt;P&gt;255 is an exit code from a python function (probably os.subprocess) and is probably related to file permissions on the disk.&lt;/P&gt;

&lt;P&gt;Is the splunkd process running as the correct user?  Did it run as root once and now it's running as less priveleged user now?  &lt;/P&gt;

&lt;P&gt;You may need to recursively chown the Splunk directory 'chown -Rf splunkuser:splunkgroup /path/to/splunk' after stopping Splunkd and insuring it will start as the correct user next time.&lt;/P&gt;

&lt;P&gt;This is linux right?&lt;/P&gt;</description>
    <pubDate>Sun, 06 Mar 2016 12:36:43 GMT</pubDate>
    <dc:creator>jkat54</dc:creator>
    <dc:date>2016-03-06T12:36:43Z</dc:date>
    <item>
      <title>Getting errors for every search I run</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Getting-errors-for-every-search-I-run/m-p/234258#M188483</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;I am getting below error for every search I am rinning for Summary indexing.&lt;/P&gt;

&lt;P&gt;Search process did not exit cleanly, exit_code=255, description="exited with code 255". Please look in search.log for this peer in the Job Inspector for more info.&lt;/P&gt;

&lt;P&gt;This error is coming for all the indexers.&lt;/P&gt;

&lt;P&gt;I have read couple of splunk annwers and then removed huge csv's from lookups directory by blacklisting them from distsearch.conf, but still my searches are failing.&lt;/P&gt;

&lt;P&gt;I am not able to do this :&lt;BR /&gt;
index=summary&lt;/P&gt;

&lt;P&gt;It throws error.&lt;BR /&gt;
I checked the size of the bundles on search heads and indexers and the size of the bundle is same.&lt;BR /&gt;
Then why am  I getting error while searching.&lt;/P&gt;

&lt;P&gt;Thanks , &lt;BR /&gt;
Usha&lt;/P&gt;</description>
      <pubDate>Sun, 06 Mar 2016 10:47:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Getting-errors-for-every-search-I-run/m-p/234258#M188483</guid>
      <dc:creator>usha_nittala</dc:creator>
      <dc:date>2016-03-06T10:47:04Z</dc:date>
    </item>
    <item>
      <title>Re: Getting errors for every search I run</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Getting-errors-for-every-search-I-run/m-p/234259#M188484</link>
      <description>&lt;P&gt;Splunk version is 6.1.4&lt;/P&gt;</description>
      <pubDate>Sun, 06 Mar 2016 10:47:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Getting-errors-for-every-search-I-run/m-p/234259#M188484</guid>
      <dc:creator>usha_nittala</dc:creator>
      <dc:date>2016-03-06T10:47:33Z</dc:date>
    </item>
    <item>
      <title>Re: Getting errors for every search I run</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Getting-errors-for-every-search-I-run/m-p/234260#M188485</link>
      <description>&lt;P&gt;Open the job inspector and look in search.log for errors and post any you find there.&lt;/P&gt;

&lt;P&gt;255 is an exit code from a python function (probably os.subprocess) and is probably related to file permissions on the disk.&lt;/P&gt;

&lt;P&gt;Is the splunkd process running as the correct user?  Did it run as root once and now it's running as less priveleged user now?  &lt;/P&gt;

&lt;P&gt;You may need to recursively chown the Splunk directory 'chown -Rf splunkuser:splunkgroup /path/to/splunk' after stopping Splunkd and insuring it will start as the correct user next time.&lt;/P&gt;

&lt;P&gt;This is linux right?&lt;/P&gt;</description>
      <pubDate>Sun, 06 Mar 2016 12:36:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Getting-errors-for-every-search-I-run/m-p/234260#M188485</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2016-03-06T12:36:43Z</dc:date>
    </item>
  </channel>
</rss>

