I love the new Splunk-On-Splunk utility (it has saved us a ton of grief and sieved through logs for us). This tool saved us a ton of grief in terms of problems in config files and debris that must be isolated and removed from some of our setup for Splunk.
Our configuration is one search head and multiple search peers (these peers are VMs that are currently turned OFF at the moment). No data is incoming and outbound to them.
Most of what Splunk-On-Splunk revealed to us were warnings.
We do however, keep getting this error and I am clueless about what it could potentially be
-0800 ERROR HTTPClient - Invalid URI fragment "": can't find hostname
Anybody know what HTTPClient is and what role it plays in the Splunk scheme of things ?
If its an ERROR as reported by S.o.S, to me, I have to fix it (even though it does not break a dashboard or a view)
Are you running deployment monitor? If so, you may be hitting SPL-63568 (located here - Splunk Known Issues
Current work around is to delete any stanza's referring to dm_license_summary_10m_by_indexer in etc/apps/splunk_deployment_monitor/default/savedsearches.conf.
I have a similar error, did you ever figure out what it means? Thanks.