I am in a an index cluster environment which shows me the following error on all indexers:
ERROR DispatchCommandProcessor - Search results may be incomplete, peer YYYY's search ended prematurely. Error = failed to rename src=D:\Splunk\var\run\splunk\cluster\search-buckets\search_site2_gen349191_1517832906.155032_tmp.csv.gz, dst=D:\Splunk\var\run\splunk\cluster\search-buckets\search_site2_gen349191.csv.gz, rv=5.
Has anyone seen this before? How can I fix this?
Looks like the permissions are wrong on the file paths.
You need to recursively take ownership of the splunk directory with the service account you are using (local system if you installed without a managed service account).
View solution in original post
Fixed it by repairing permissions using icacls.exe /T /Q /P /reset. Thanks!