When running | datamodel Intrusion_Detection search
I get the following error message for each indexer -
[<indexer name>] Search process did not exit cleanly, exit_code=255, description="exited with code 255". Please look in search.log for this peer in the Job Inspector for more info.
What can it be?
Hi danielbb,
check the OS logs of your indexer, one of the reasons for this can be that your search job was killed by OOM (Out of Memory) Killer .. assuming you are running the indexers on nix.
cheers, MuS
@MuS, I've been working with Support on that and we found out that all the indexers throw the following error -
-- 10-16-2019 16:03:39.534 ERROR SearchParser - The search specifies a macro varonis_index
that cannot be found. Reasons include: the macro name is misspelled, you do not have "read" permission for the macro, or the macro has not been shared with this application. Click Settings, Advanced search, Search Macros to view macro information.
We also saw that when running index=_internal
, we see the same error (many times), but in the case of index=_internal
, this error doesn't prevent the command from completing its work and display the results.
A similar thread at ERROR SearchParser - The search specifies a macro 'cs_get_index' that cannot be found.
Support is saying that every search I submit is checked against my eventtype.conf
s
A continuation thread about this case is at How come a specific macro ends up in generic searches and breaks some of them?