Getting Data In

After configuring configure yarn variables, why does my search fail to run?

jmallorquin
Builder

Hi,

I configured the YARN variables needed in the provider, but now the search query I try to run fails.

It looks like is not able to find the mapreduce.jobhistory.address but i don't know where to define.

com.splunk.mr.JobStartException: Failed to start MapReduce job. Please consult search.log for more information. Message: java.net.ConnectException: Call From Cloudera04/172.xx.x.xxx to 0.0.0.0:10020

Any advice?

Thanks,

Tags (3)
0 Karma
1 Solution

rdagan_splunk
Splunk Employee
Splunk Employee

You most likely be able to find the value for this flag ( mapreduce.jobhistory.address ) under http:// < resource manager ip > : 8088 / conf

View solution in original post

0 Karma

rdagan_splunk
Splunk Employee
Splunk Employee

You most likely be able to find the value for this flag ( mapreduce.jobhistory.address ) under http:// < resource manager ip > : 8088 / conf

0 Karma

jmallorquin
Builder

Hi rdagan,

It was working until this message appears:

ChunkedOutputStreamReader: Invalid transport header line="194.xxx.xx.185 194.xxx.xx.185 - [15/Nov/2016:11:22:38 +0100] "GET /stat/ebanking/min/css/img_s24/menu/menu-stin.png HTTP/1.1" 200 150 "https://www.mycompany.cz/stat/ebanking/min/css/global_s24.css?v=37_prod.25" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2840.99 Safari/537.36" "17850" TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 0" 

Any advice?

Thanks again

0 Karma

jmallorquin
Builder

Hi rdagan

mapreduce.jobhistory.address0.0.0.0:10020mapred-default.xml

this is what i get

0 Karma

rdagan_splunk
Splunk Employee
Splunk Employee

what about Cloudera Manager or mapred-site.xml?

0 Karma

jmallorquin
Builder

The same value

0 Karma

rdagan_splunk
Splunk Employee
Splunk Employee

So once you find this value, you can add this flag to the Provider. Just add vix before the flag. For example, vix.mapreduce.jobhistory.address

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...