Deployment Architecture

Seeing recurring error "Timeliner - Failed to rm dir" even though permissions are correct...

tmeader
Contributor

We've been seeing the same error as originally mentioned in this older question:

http://answers.splunk.com/questions/11607/4-1-7-upgrade-from-4-1-4-new-error-message-failed-to-rm-di...

Haven't seen any further insight from anyone at Splunk on this, was just wondering if any conclusion was ever reached as to the cause of this error. To be specific, we're seeing lines like the following after nearly every search that's executed (note: the searched finish fine in the interface, and, at least in the web gui, everything seems normal):

03-29-2011 22:26:44.014 ERROR Timeliner - Failed to rm dir /opt/splunk/var/run/splunk/dispatch/searchparsetmp_607175023/buckets: No such file or directory

Going by the advice in the aforementioned question, we've confirmed that all necessary ownership and permissions are set properly all the way through to (and including) the "dispatch" directory. Likewise, the directories mentioned in these messages are being removed properly after the searches finish their natural lifespan. I'm not sure what's causing the generation of these errors from the "Timeliner". It's as if it isn't aware that the searches are completing properly, and is trying to cleanup the directories after the fact.

Any insight or suggestions on further debugging this would be greatly appreciated.

1 Solution

yannK
Splunk Employee
Splunk Employee

Please disregards this Error message, it's not a relevant one.

This is a know bug "SPL-38078" and "SPL-35722", and will be fixed in next releases (4.1.8).

View solution in original post

yannK
Splunk Employee
Splunk Employee

Please disregards this Error message, it's not a relevant one.

This is a know bug "SPL-38078" and "SPL-35722", and will be fixed in next releases (4.1.8).

fox
Path Finder

are you on Windows?

We have found some permissioning issues with Windows installations and have manually changed permissions on all sub directories and files...

0 Karma

tmeader
Contributor

Nope, this is CentOS 5.5 x64. We've checked all file/directory ownership and permissions though... it's definitely not that. The fact of the matter is, the directories do not exist (were already removed) yet Splunk keeps trying to after the fact for some reason.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...