Deployment Architecture

How to fix Splunk search head pool "Error in dispatch process. Failed to create directory /data/var/run/dispatch/xyz"?

pdash
Path Finder

Error in search head pooling validate-quiet: Failed to create test file: /data/etc/users/testpath: Disk quota exceeded
There was an error validating your search head pooling configuration. For more information, run 'splunk pooling validate'
Error fixing dangling data: Failed to lock /data/etc/apps/sentinel.txt with code -1, possible reason: No such file or directory
There was an error preparing your conf files for search head pooling. For more information, run 'splunk btool find-dangling'.

This is the error am getting when i restart my search head and it doesnt allow me to to search once it started "Error in dispatch process. Failed to create directory /data/var/run/dispatch/xyz"

0 Karma

jmheaton
Path Finder

Assuming your using pooling, then i would verify that all of your servers in the pool are running with the correct permissions. This had happened to us a couple months ago when we spun up a new search head and it was running as a user that didn't have permissions to read and write all the files in the pool.

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...