<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: [UPDATE] Pivot searches erroring out with: Error in 'TSCollectProcessor' in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/UPDATE-Pivot-searches-erroring-out-with-Error-in/m-p/84142#M21464</link>
    <description>&lt;P&gt;The pivot breaks immediately...well after 0.42 seconds.  Here's the event from the _audit index: Audit:[timestamp=10-28-2013 01:49:43.876, user=n/a, action=search, info=failed, search_id='1382924973.2275', total_run_time=0.42, event_count=1555, result_count=0, available_count=0, scan_count=1555, drop_count=0, exec_time=1382924973, api_et=N/A, api_lt=N/A, search_et=N/A, search_lt=N/A, is_realtime=0, savedsearch_name=""][n/a]&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 15:05:49 GMT</pubDate>
    <dc:creator>gauldridge</dc:creator>
    <dc:date>2020-09-28T15:05:49Z</dc:date>
    <item>
      <title>[UPDATE] Pivot searches erroring out with: Error in 'TSCollectProcessor'</title>
      <link>https://community.splunk.com/t5/Splunk-Search/UPDATE-Pivot-searches-erroring-out-with-Error-in/m-p/84138#M21460</link>
      <description>&lt;P&gt;I have a Splunk instance out on Amazon EC2 that I have used for demo purposes for a long time.  It's just indexing the Apache logs and audit logs of the EC2 so I have data for demos.&lt;/P&gt;

&lt;P&gt;I just upgraded to Splunk 6 from Splunk 5.0.3.  I was having no issues with Splunk 5.0.3 but with version 6 I am not able demo the Pivot functionality (which is the main feature I have been wanting show during the past week) because it errors out immediately.  The full error message I am given is:&lt;/P&gt;

&lt;P&gt;Error in 'TSCollectProcessor': Failed to create TSIDX event in namespace='/opt/splunk/var/run/splunk/dispatch/1380974044.171/tsidxstats' errcode=1 &lt;/P&gt;

&lt;P&gt;I get this error message for Data Models I have created as well as the two sample Data Models provided with the install.  I get no errors using the regular search functions.&lt;/P&gt;

&lt;P&gt;I should mention that I upgraded from version 5.0.3 to version 6 on physical hardware and have no issues whatsoever.  It's only the EC2 demo instance that I'm having issues with post-upgrade.&lt;/P&gt;

&lt;P&gt;Any ideas out there on how I can get my demo instance of Splunk up and running?&lt;/P&gt;

&lt;P&gt;UPDATE: The DEBUG info in the job inspector is: DEBUG: search context: user="marty", app="search", bs-pathname="/opt/splunk/etc"&lt;/P&gt;

&lt;P&gt;2nd UPDATE: The Pivot will work properly only if the Data Model includes one additional Attribute.  For example, it will work properly if I add clientip but it will break if I add another field.&lt;/P&gt;</description>
      <pubDate>Sat, 05 Oct 2013 12:12:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/UPDATE-Pivot-searches-erroring-out-with-Error-in/m-p/84138#M21460</guid>
      <dc:creator>gauldridge</dc:creator>
      <dc:date>2013-10-05T12:12:41Z</dc:date>
    </item>
    <item>
      <title>Re: [UPDATE] Pivot searches erroring out with: Error in 'TSCollectProcessor'</title>
      <link>https://community.splunk.com/t5/Splunk-Search/UPDATE-Pivot-searches-erroring-out-with-Error-in/m-p/84139#M21461</link>
      <description>&lt;P&gt;Are you relatively low on disk space?  See the first item &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.0/Installation/Aboutupgradingto6.0READTHISFIRST#Other_notable_changes"&gt;here&lt;/A&gt;:&lt;/P&gt;

&lt;P&gt;We have increased the default amount of required available disk space for indexing and searching&lt;/P&gt;

&lt;P&gt;Prior to version 6.0, the default amount of free space Splunk needed to index and search was 2 gigabytes. When you upgrade, Splunk raises this default requirement to 5 gigabytes. Before you upgrade, make sure you have enough free space on the volume(s) that contain Splunk indexes and search dispatch directories to ensure uninterrupted index and search operation&lt;/P&gt;</description>
      <pubDate>Sun, 06 Oct 2013 06:07:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/UPDATE-Pivot-searches-erroring-out-with-Error-in/m-p/84139#M21461</guid>
      <dc:creator>jspears</dc:creator>
      <dc:date>2013-10-06T06:07:41Z</dc:date>
    </item>
    <item>
      <title>Re: [UPDATE] Pivot searches erroring out with: Error in 'TSCollectProcessor'</title>
      <link>https://community.splunk.com/t5/Splunk-Search/UPDATE-Pivot-searches-erroring-out-with-Error-in/m-p/84140#M21462</link>
      <description>&lt;P&gt;I had not considered the minimum disk space requirement. However, after checking the available disk space on my EC2, I have a little over 6GB free space. The logs being indexed by this instance are very low volume and shouldn't consume the 1GB+ buffer for a good while.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2013 03:05:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/UPDATE-Pivot-searches-erroring-out-with-Error-in/m-p/84140#M21462</guid>
      <dc:creator>gauldridge</dc:creator>
      <dc:date>2013-10-07T03:05:37Z</dc:date>
    </item>
    <item>
      <title>Re: [UPDATE] Pivot searches erroring out with: Error in 'TSCollectProcessor'</title>
      <link>https://community.splunk.com/t5/Splunk-Search/UPDATE-Pivot-searches-erroring-out-with-Error-in/m-p/84141#M21463</link>
      <description>&lt;P&gt;Any other errors in the search.log for the dispatch directory of the tscollect job? That would be helpful in debugging this.&lt;/P&gt;

&lt;P&gt;I can't imagine how changing the amount of attributes would affect this specific code path to yield this errcode, so we need a bit more information. Is it breaking immediately in pivot or after it's been running for a bit? If it's the latter, I'd suspect disk space issues.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2013 22:15:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/UPDATE-Pivot-searches-erroring-out-with-Error-in/m-p/84141#M21463</guid>
      <dc:creator>Marklar</dc:creator>
      <dc:date>2013-10-09T22:15:30Z</dc:date>
    </item>
    <item>
      <title>Re: [UPDATE] Pivot searches erroring out with: Error in 'TSCollectProcessor'</title>
      <link>https://community.splunk.com/t5/Splunk-Search/UPDATE-Pivot-searches-erroring-out-with-Error-in/m-p/84142#M21464</link>
      <description>&lt;P&gt;The pivot breaks immediately...well after 0.42 seconds.  Here's the event from the _audit index: Audit:[timestamp=10-28-2013 01:49:43.876, user=n/a, action=search, info=failed, search_id='1382924973.2275', total_run_time=0.42, event_count=1555, result_count=0, available_count=0, scan_count=1555, drop_count=0, exec_time=1382924973, api_et=N/A, api_lt=N/A, search_et=N/A, search_lt=N/A, is_realtime=0, savedsearch_name=""][n/a]&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:05:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/UPDATE-Pivot-searches-erroring-out-with-Error-in/m-p/84142#M21464</guid>
      <dc:creator>gauldridge</dc:creator>
      <dc:date>2020-09-28T15:05:49Z</dc:date>
    </item>
    <item>
      <title>Re: [UPDATE] Pivot searches erroring out with: Error in 'TSCollectProcessor'</title>
      <link>https://community.splunk.com/t5/Splunk-Search/UPDATE-Pivot-searches-erroring-out-with-Error-in/m-p/84143#M21465</link>
      <description>&lt;P&gt;Check the memory usage - the smallest micro AMI that Amazon provides doesn't have enough RAM to allow the Pivot interface to function correctly.&lt;/P&gt;</description>
      <pubDate>Mon, 05 May 2014 17:45:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/UPDATE-Pivot-searches-erroring-out-with-Error-in/m-p/84143#M21465</guid>
      <dc:creator>pj</dc:creator>
      <dc:date>2014-05-05T17:45:17Z</dc:date>
    </item>
  </channel>
</rss>

