Deployment Architecture

In a diag for UniversalForwarder/LightWeightForwarder, var/lib/splunk/fishbucket/db is empty?

zliu
Splunk Employee
Splunk Employee

After ran a diag for UniversalForwarder/LightWeightForwarder, found that var/lib/splunk/fishbucket/db is empty. Anything is not right?

Tags (1)
1 Solution

zliu
Splunk Employee
Splunk Employee

on recent versions of UF and LWF(4.2.x), systeminfo.txt's "find" section is not reporting directory listings correctly - it is always empty. Until this is fixed, we will have to manually do an ls -lR on $SPLUNK_DB/fishbucket. Bug: SPL-41886.

View solution in original post

zliu
Splunk Employee
Splunk Employee

on recent versions of UF and LWF(4.2.x), systeminfo.txt's "find" section is not reporting directory listings correctly - it is always empty. Until this is fixed, we will have to manually do an ls -lR on $SPLUNK_DB/fishbucket. Bug: SPL-41886.

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...