Deployment Architecture

CMSlave - Error deserializing notify

lukasz92
Communicator

I have many entries like this:

WARN CMSlave - event=handleNotifySummaries error deserializing notify file=/raid/splunk/var/lib/splunk/websphere/datamodel_summary/notify/notify.1_7B6E7EF6-00F8-45EC-876E-4E57B8B867C3.08E505C1-07CE-4046-820E-A8FCD7CEA32C_DM_(...).MSExchange err=invalid notify summary file=notify.1_7B6E7EF6-00F8-45EC-876E-4E57B8B867C3.08E505C1-07CE-4046-820E-A8FCD7CEA32C_DM_(...).MSExchange

What does it mean?

I have 2 indexers on site1 and 2 on site2; all connected to Cluster Master.

0 Karma

dxu_splunk
Splunk Employee
Splunk Employee

This can be safely ignored as long as you're not using summary replication. (If using summary replication, these summaries will not be replicated amongst the cluster, and a workaround would be to rename the DataModel/ReportAcceleration to remove any "." in the name)

maraman_splunk
Splunk Employee
Splunk Employee

Hmm, same kind of warning here.
Don't know if there's any impact
splunk 6.4.1, linux redhat 6.8 64bit, ext4
I've got 4 new indexers in CM, all have the same warnings...

0 Karma

woodcock
Esteemed Legend

Open a support case.

0 Karma

koshyk
Super Champion

same error here. Need to be fix from splunk

0 Karma

dxu_splunk
Splunk Employee
Splunk Employee

its been fixed in 6.4.3

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...

Federated Search for CloudWatch Unified Data Store Is Generally Available

As organizations modernize their cloud environments, AWS workloads generate more security, operational, and ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...