Getting Data In

After setting up a universal forwarder and receiver on Windows, why am I getting "Error in 'DispatchProcess': Failed to write the info file to C:\Program Files\Splunk\var\run\splunk\dispatch\[lots of letters and numbers]\info.csv"?

mr_dombat
Explorer

I've set up a universal forwarder on a remote webserver using local system account (Win2008R2 64bit).

I have enabled receiving on the receiver which is using a domain account (Win7 Pro 64bit). It asked to restart Splunk which I did.

The dashboard is now showing:

Error in 'DispatchProcess': Failed to write the info file to C:\Program Files\Splunk\var\run\splunk\dispatch\[lots of letters and numbers]\info.csv
0 Karma

nbjoshi_splunk
Splunk Employee
Splunk Employee

Are you sure you installed the Splunk Universal Forwarder and not a full Splunk installation? I would expect the directory to be C:\Program Files\SplunkUniversalForwarder....

In regards to your error, you might have some old erroneous results stored in the dispatch directory. You can manually clear out the "[lots of letters and numbers]" directory and restart Splunk and this should resolve the issue.

0 Karma

mr_dombat
Explorer

The error message was manifesting itself in the full splunk.

On the indexer/receiver I deleted the files as requested it made no difference.

I changed the two services to run as interactive desktop enabled LocalService and restarted splunk, same messages.

I checked permissions on the folder(s) and added my domain and localsevice both as Full control, restarted, same messages.

I uninstalled Splunk, cleaned the registry using CCLeaner, rebooted, reinstalled using Local account (default setting) and it seems OK now.

Not getting anything from my forwarders still but that is a different question.

0 Karma
Get Updates on the Splunk Community!

Data Preparation Made Easy: SPL2 for Edge Processor

By now, you may have heard the exciting news that Edge Processor, the easy-to-use Splunk data preparation tool ...

Introducing Edge Processor: Next Gen Data Transformation

We get it - not only can it take a lot of time, money and resources to get data into Splunk, but it also takes ...

Tips & Tricks When Using Ingest Actions

Tune in to learn about:Large scale architecture when using Ingest ActionsRegEx performance considerations ...