Getting Data In

After upgrade to Splunk Enterprise 6.3 we are receiving "Failed to fetch REST endpoint uri=https://127.0.0.1:8089/services/licenser/slaves?count=0 from server=https://127.0.0.1:8089"

peter5687
Engager

Since upgrading to Splunk version 6.3 we are receiving in the splunkd.log every 10 mins :

ERROR SearchOperator:rest - sid:subsearch_summarize_1443565748.14869_1443565748.14870 Failed to fetch REST endpoint uri=https://127.0.0.1:8089/services/licenser/slaves?count=0 from server=https://127.0.0.1:8089
1 Solution

Plotkowski
Path Finder

I think i found a solution.
We upgraded from 5 to 6.3 and got the same problem.
The deployment monitor is deprecated since 6.3 and it seems like this is causing this error.

We removed the deployment monitor, restarted splunk and no longer get this error message.
I hope this helps.

View solution in original post

Plotkowski
Path Finder

I think i found a solution.
We upgraded from 5 to 6.3 and got the same problem.
The deployment monitor is deprecated since 6.3 and it seems like this is causing this error.

We removed the deployment monitor, restarted splunk and no longer get this error message.
I hope this helps.

mookiie2005
Communicator

How did you remove the deployment monitor? Did you delete the folder within splunk\etc\apps? Or disable it through the apps management GUI?

0 Karma

frobinson_splun
Splunk Employee
Splunk Employee

Hello @peter5687,
I'm a tech writer here at Splunk and I work on our REST API documentation. I'm running your comment by our engineering team and will report back. Are you still seeing this issue? Have you contacted support?

Thanks for any further details,
@frobinson_splunk

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...