All Apps and Add-ons

SA-geodistance app - remedy for "buffer full" error?

wryanthomas
Contributor

Hi there. Thanks for this app!

I'm experiencing the following error when passing high record volume to geodistance command (in both Splunk Enterprise and Splunk Cloud):

ERROR ChunkedExternProcessor - Failure writing result chunk, buffer full. External process possibly failed to read its stdin.

According to another post on answers.splunk.com, it looks like someone (kulick?) might have a solution to this issue:
https://answers.splunk.com/answers/686940/how-come-custom-search-commands-csc-scpv2-cannot-h.html

He references a fix in git hub: "The solution is embodied in the new 'echo' custom command implemented in this change...
https://github.com/TiVo/splunk-sdk-python/commit/5188f7d709cadd80e786692b371a64c4ae0991d2

There is additional reporting of this issue here:
https://github.com/splunk/splunk-sdk-python/issues/150

Would it be possible to investigate this for a possible fix?

Tags (1)
0 Karma

seunomosowon
Communicator

Yes that'll work nicely. I'll try incorporate it into the app next week.

0 Karma

wryanthomas
Contributor

Excellent. Any update?

0 Karma

wryanthomas
Contributor

Hey there. Just checking in. Is this still in the works?

0 Karma

wryanthomas
Contributor

Hi @seunomosowon . I see in Splunkbase that this app was updated to v1.2.0 on 12/28/2020.

I'm not seeing any indication in the Details page that this "buffer full" issue was addressed.

Any chance there's a fix for this on the way?

 

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...