Deployment Architecture

How to fix Splunk search head pool "Error in dispatch process. Failed to create directory /data/var/run/dispatch/xyz"?

pdash
Path Finder

Error in search head pooling validate-quiet: Failed to create test file: /data/etc/users/testpath: Disk quota exceeded
There was an error validating your search head pooling configuration. For more information, run 'splunk pooling validate'
Error fixing dangling data: Failed to lock /data/etc/apps/sentinel.txt with code -1, possible reason: No such file or directory
There was an error preparing your conf files for search head pooling. For more information, run 'splunk btool find-dangling'.

This is the error am getting when i restart my search head and it doesnt allow me to to search once it started "Error in dispatch process. Failed to create directory /data/var/run/dispatch/xyz"

0 Karma

jmheaton
Path Finder

Assuming your using pooling, then i would verify that all of your servers in the pool are running with the correct permissions. This had happened to us a couple months ago when we spun up a new search head and it was running as a user that didn't have permissions to read and write all the files in the pool.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...