All Apps and Add-ons

fire brigade errors

a212830
Champion

Hi,

I have the latest fire brigade installed on a 6.4.1 SHC (and the appropriate TA on the indexers). I'm getting the following errors from "cumulatize usage over all hosts panel" in the the cross-host index overview page.

[subsearch]: Failed to fetch REST endpoint uri=https://127.0.0.1:8089/services/data/indexes/dh_clocksync?count=0&search=disabled%3D0 from server=https://127.0.0.1:8089
[subsearch]: Unexpected status for to fetch REST endpoint uri=https://127.0.0.1:8089/services/data/indexes/dh_clocksync?count=0&search=disabled%3D0 from server=https://127.0.0.1:8089 - Not Found

0 Karma

sowings
Splunk Employee
Splunk Employee

I'll put good money on the fact that the "dh_clocksync" index doesn't exist on your search head(s).

0 Karma

sowings
Splunk Employee
Splunk Employee

To elaborate on my answer a bit more: Those pages will attempt a REST query to find out about the configured retention limits for the index. The purpose is to be able to report "% of capacity" as compared to current usage. The SH will attempt to do this across all hosts, including itself. If the index definition for dh_clocksync only exists on the indexers, the SH (127.0.0.1) will report the error you see.

You might consider the Troubleshooting menu, the "Troubleshooting Index Configuration" to see which host(s) don't have that index.

0 Karma

sloshburch
Splunk Employee
Splunk Employee

What answer/insight are you looking for? I ask because it might be available in the DMC now (and if not, we can let the DMC team know). I have DMC bias...

Psst: I think you mean Fire Brigade, not Fire Bridge.

0 Karma

sowings
Splunk Employee
Splunk Employee

Oh Burch, why no love?!

0 Karma

sloshburch
Splunk Employee
Splunk Employee

😉 I figured if I was disparaging enough it would be like a Bat-Signal and get you running 😉

0 Karma

a212830
Champion

That's part of what I'm trying to determine - do I need fire brigade.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...