<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Warning in internal log: unable to parse site_label in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Warning-in-internal-log-unable-to-parse-site-label/m-p/602824#M209831</link>
    <description>&lt;P&gt;Plus ca change ...&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.0/ReleaseNotes/Knownissues" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.0/ReleaseNotes/Knownissues&lt;/A&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;2021-09-22&lt;/TD&gt;&lt;TD&gt;SPL-212495, SPL-196040, SPL-219811&lt;/TD&gt;&lt;TD&gt;Excessive logging 'WARN SearchResultsFiles Unable to parse site_label, label=invalid due to err="Invalid site id: invalid"' for SearchResultsFiles&lt;BR /&gt;&lt;BR /&gt;Workaround:&lt;BR /&gt;none&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
    <pubDate>Wed, 22 Jun 2022 14:46:46 GMT</pubDate>
    <dc:creator>vgrote</dc:creator>
    <dc:date>2022-06-22T14:46:46Z</dc:date>
    <item>
      <title>Warning in internal log: unable to parse site_label</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Warning-in-internal-log-unable-to-parse-site-label/m-p/538756#M152330</link>
      <description>&lt;P&gt;I recently noticed a huge amount of warnings in the _internal logs for our search heads. events are all like this:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;02-04-2021 12:22:08.485 +0300 WARN  SearchResultsFiles - Unable to parse site_label, label=invalid due to err="Invalid site id: invalid"&lt;/LI-CODE&gt;&lt;P&gt;We are running a distributed environment with a search head cluster and all installations are Splunk 8.1.1. The warnings are logged only on the search heads.&lt;/P&gt;&lt;P&gt;When investigating i see this has occured for quite som time but i'm very qurious as to what this means.&amp;nbsp; There are no other indications in the _internal log that hints to why this warning keep appearing. I have however discovered that it seems to maybe be related to lookups and perhaps the kvstore. The reason i think so is that i can't force this warning when doing normal searches, but when i open dashbords that uses searches with macros and lookups they appear immediately. I've tried several different dashboards and searches and it seems consistent that anything with a lookup will produce this warning.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm further thinking this might have happened when we upgraded to Splunk 8.1.1 recently. I've got two standalone servers for test purposes where one is running Splunk 8.1.1 and the other one is running Splunk 8.1.0.1&lt;BR /&gt;I have not been able to force this warning on the Splunk instance running 8.1.0.1 as of yet, but the one running 8.1.1 will have these warnings when i open dashbords and advanced searches.&lt;/P&gt;&lt;P&gt;I have not found anything in the Splunk "known issues" about this warning specifically. I don't even know if it causes any problems other than filling up the _internal log (There are noe issues with our environment relating to this warning as far as i know).&lt;/P&gt;&lt;P&gt;So i was wondering if anyone else have been experiencing these warnings, know what they are and know how to stop them? In peak search time there can be several million events per hour.&amp;nbsp;&lt;/P&gt;&lt;P&gt;One thing i have not yet tried, but will try as soon as possible, is to upgrade one of the standalone servers to Splunk 8.1.2 and see if that fixes things.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 12:43:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Warning-in-internal-log-unable-to-parse-site-label/m-p/538756#M152330</guid>
      <dc:creator>mortf</dc:creator>
      <dc:date>2021-02-05T12:43:55Z</dc:date>
    </item>
    <item>
      <title>Re: Warning in internal log: unable to parse site_label</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Warning-in-internal-log-unable-to-parse-site-label/m-p/538771#M152335</link>
      <description>&lt;P&gt;Check the &lt;FONT face="courier new,courier"&gt;site&lt;/FONT&gt; settings in server.conf on all search heads.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 14:06:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Warning-in-internal-log-unable-to-parse-site-label/m-p/538771#M152335</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-02-05T14:06:31Z</dc:date>
    </item>
    <item>
      <title>Re: Warning in internal log: unable to parse site_label</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Warning-in-internal-log-unable-to-parse-site-label/m-p/539003#M152438</link>
      <description>&lt;P&gt;The server.conf i /etc/system/local is the same on all search heads and there are no specific site settings there, so all of them should follow the default site settings from the /etc/system/default server.conf&lt;/P&gt;&lt;P&gt;I asked this same question in slack and someone there told me that the issue i'm experiencing is a bug in the current major release version of Splunk. The issue will be fixed in the next major release version and so i'm choosing this as the answer to my question. There does not seem to be a viable workaround.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 14:34:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Warning-in-internal-log-unable-to-parse-site-label/m-p/539003#M152438</guid>
      <dc:creator>mortf</dc:creator>
      <dc:date>2021-02-08T14:34:08Z</dc:date>
    </item>
    <item>
      <title>Re: Warning in internal log: unable to parse site_label</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Warning-in-internal-log-unable-to-parse-site-label/m-p/572098#M199367</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/151319"&gt;@mortf&lt;/a&gt;&amp;nbsp;I'm also experiencing this issue, the following error message is flooding my splunkd.log:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;WARN SearchResultsFiles - Unable to parse site_label, label=invalid due to err="Invalid site id: invalid"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you confirm upgrading to a later version of Splunk resolved your issue? If so, what version did you upgrade to?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Oct 2021 03:03:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Warning-in-internal-log-unable-to-parse-site-label/m-p/572098#M199367</guid>
      <dc:creator>orion44</dc:creator>
      <dc:date>2021-10-23T03:03:05Z</dc:date>
    </item>
    <item>
      <title>Re: Warning in internal log: unable to parse site_label</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Warning-in-internal-log-unable-to-parse-site-label/m-p/572139#M199399</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;Upgrading to a new version of Splunk did not resolve this issue. The newest splunk version has this listet under known issues as well. Check out&amp;nbsp;&lt;SPAN&gt;SPL-212495 and SPL-196040.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Oct 2021 07:55:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Warning-in-internal-log-unable-to-parse-site-label/m-p/572139#M199399</guid>
      <dc:creator>mortf</dc:creator>
      <dc:date>2021-10-24T07:55:26Z</dc:date>
    </item>
    <item>
      <title>Re: Warning in internal log: unable to parse site_label</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Warning-in-internal-log-unable-to-parse-site-label/m-p/597361#M207974</link>
      <description>&lt;P&gt;V8.2.6 - Still not fixed.&lt;/P&gt;&lt;P&gt;&lt;A title="8.2.6 Release Notes Known Issues" href="https://docs.splunk.com/Documentation/Splunk/8.2.6/ReleaseNotes/Knownissues" target="_self"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.6/ReleaseNotes/Knownissues&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;SPL-212495, SPL-196040, SPL-219811
Excessive logging 'WARN SearchResultsFiles Unable to parse site_label, label=invalid due to err="Invalid site id: invalid"' for SearchResultsFiles
Workaround: none&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 11 May 2022 11:06:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Warning-in-internal-log-unable-to-parse-site-label/m-p/597361#M207974</guid>
      <dc:creator>dfronck</dc:creator>
      <dc:date>2022-05-11T11:06:06Z</dc:date>
    </item>
    <item>
      <title>Re: Warning in internal log: unable to parse site_label</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Warning-in-internal-log-unable-to-parse-site-label/m-p/602824#M209831</link>
      <description>&lt;P&gt;Plus ca change ...&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.0/ReleaseNotes/Knownissues" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.0/ReleaseNotes/Knownissues&lt;/A&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;2021-09-22&lt;/TD&gt;&lt;TD&gt;SPL-212495, SPL-196040, SPL-219811&lt;/TD&gt;&lt;TD&gt;Excessive logging 'WARN SearchResultsFiles Unable to parse site_label, label=invalid due to err="Invalid site id: invalid"' for SearchResultsFiles&lt;BR /&gt;&lt;BR /&gt;Workaround:&lt;BR /&gt;none&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Wed, 22 Jun 2022 14:46:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Warning-in-internal-log-unable-to-parse-site-label/m-p/602824#M209831</guid>
      <dc:creator>vgrote</dc:creator>
      <dc:date>2022-06-22T14:46:46Z</dc:date>
    </item>
    <item>
      <title>Re: Warning in internal log: unable to parse site_label</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Warning-in-internal-log-unable-to-parse-site-label/m-p/645800#M223596</link>
      <description>&lt;P&gt;This appears to still not have been fixed, even though we are at version 8.2.7.&lt;BR /&gt;This is very disappointing from Splunk as it fills our logs with garbage and important logs get pushed out of the historical records.&amp;nbsp;&lt;BR /&gt;Splunk engineers: This needs to be fixed now.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2023 17:59:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Warning-in-internal-log-unable-to-parse-site-label/m-p/645800#M223596</guid>
      <dc:creator>sansay1</dc:creator>
      <dc:date>2023-06-05T17:59:48Z</dc:date>
    </item>
  </channel>
</rss>

