All Apps and Add-ons

Installation of Splice App causes data model searches to fail

joshua_hart1
Path Finder

When I install and enable the Splice app on my search head, dashboards that utilize data model searches fail. Errors that I receive include:

[indexer] Search process did not exit cleanly, exit_code=255, description="exited with code 255". Please log in the search.log for this peer in the job inspector for more info.

I searched the search.log and there is nothing that indicates why the search would exit. Is there a configuration within the Splice app that would interfere with data model searches?

Tags (3)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Make sure you also examine the search.log of indexers - by default those are not sent to the search head.

0 Karma

cleroux_splunk
Splunk Employee
Splunk Employee

SPLICE do not uses the data model searches. I don't see any reason nor configuration element that could interfere with the data model searches.

0 Karma

joshua_hart1
Path Finder

Correct. However, when I perform a data model search | datamodel ... from another app, with Splice enabled, I get the error_code=255. When I disable it, I'm able to perform the searches. It appears that Splice is getting in the way.

0 Karma

cleroux_splunk
Splunk Employee
Splunk Employee

They are similar issues already reported, none linked to Splice so far, did you deployed Splice on your Indexers as well?

Ex: http://answers.splunk.com/answers/131053/solved-error-banner-message-exit-code-255-btool-command.htm...

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...