All Apps and Add-ons

Hadoop Virtual Index - No Results Found

tt1
Explorer

Guys,

First day using hunk/splunk. I seem to be set up ok but just can not get anything returned form a Virtual Index.

The index is pointing to a correct HDFS directory with permissions.

Is there anything obvious I may not be doing correctly? Any answers appreciated?

Regards.

Tags (2)
1 Solution

Ledion_Bitincka
Splunk Employee
Splunk Employee

It seems like you have incorrectly specified the HDFS port. 50070 is usually the HTTP port, you need to specify IPC/RPC port, which usually defaults to 8020. So, the solution would be to change the file system setting in the provider to: hdfs://tv-dev-clust1.tv.talktalk.lab:8020 (or whatever the port is)

02-05-2014 16:33:00.086 ERROR ERP.TestProvider -  SplunkMR$SearchHandler - Failed on local exception: com.google.protobuf.InvalidProtocolBufferException: Protocol message end-group tag did not match expected tag.; Host Details : local host is: "tv-dev-clust1.tv.talktalk.lab/10.182.14.221"; destination host is: "tv-dev-clust1.tv.talktalk.lab":50070;

View solution in original post

Ledion_Bitincka
Splunk Employee
Splunk Employee

It seems like you have incorrectly specified the HDFS port. 50070 is usually the HTTP port, you need to specify IPC/RPC port, which usually defaults to 8020. So, the solution would be to change the file system setting in the provider to: hdfs://tv-dev-clust1.tv.talktalk.lab:8020 (or whatever the port is)

02-05-2014 16:33:00.086 ERROR ERP.TestProvider -  SplunkMR$SearchHandler - Failed on local exception: com.google.protobuf.InvalidProtocolBufferException: Protocol message end-group tag did not match expected tag.; Host Details : local host is: "tv-dev-clust1.tv.talktalk.lab/10.182.14.221"; destination host is: "tv-dev-clust1.tv.talktalk.lab":50070;

tt1
Explorer

Thanks for looking in, you are right, I was using the wrong port. I tested using an incorrect IP and saw it error, but I didn't think to test the port. I am now in, the tool looks great.

0 Karma

tt1
Explorer

Hi, thanks for taking a look.

"All Time" Yes
Recurse the directory Yes

PasteBin of log http://pastebin.com/igxPPKt1

Thanks.

0 Karma

csharp_splunk
Splunk Employee
Splunk Employee

First things first, check your time picker at the right of the search bar and set it to "All Time". Did you set your virtual index to recurse the directory? You could be only looking at the top level directory. If that doesn't solve it, if you could click on Job->Inspect, scroll to the bottom, click search.log and then send us a pastebin of that, that could help us troubleshoot.

tt1
Explorer

Hi, thanks for taking a look.
"All Time" Yes
Recurse the directory Yes
PasteBin of log http://pastebin.com/igxPPKt1
Thanks.

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...