Dashboards & Visualizations

Why am I getting this dashboard error daily? "Search peer xxxxidx01 has the following message: Splunk must be restarted for changes to take effect."

splunkdeploy
New Member

Hi,

I get this error daily in my Splunk dashboard.

Error: "Search peer xxxxidx01 has the following message: Splunk must be restarted for changes to take effect."

If i restart splunk, it will be fine, but I noticed I am getting this frequently. Hence, I decided to reboot my idx VM. Once the reboot is done, the error is gone, but I get bad luck after some time and the same error occurs.

What is the issue here? In which config file I can check regarding this?

Please suggest me one permanent solution for this.

Regards,
Unni TN

0 Karma

masonmorales
Influencer

You could use the Splunk on Splunk app to look through ERRORs and WARNs in your Splunk environment to see if something is prompting a reboot. You may wish to contact Splunk Support to help diagnose the issue though.

0 Karma

splunksurekha
Path Finder

Hi,

checked under ERRORS and WARNs for that particular indexer and nothing is prompting for a reboot.
Is there a specific error which i can search for in splunkd.log or or some other log file.
Please give us some solution as we are facing this almost every day and not able to get rid of this error.

Thanks
Surekha

0 Karma

splunksurekha
Path Finder

Hi,

This is with regards to the request from Unni.

We have installed sos and looked through the errors and warns but couldn't find anything related to reboot or restart of the server.
Can you tell me what exact error i should look for.

Thanks
Surekha.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...