Getting Data In

Could not understand Splunkd.log

ma_anand1984
Contributor

I see the below in splunkd.log

ERROR AdminManager - Argument "timeout" is not supported by this handler.

UPDATE



01-04-2013 08:04:10.394 +0000 INFO AdminManager - adding validation:savedsearch validation rule alert.severity='alert.severity'>0 AND 'alert.severity'<7 ...
01-04-2013 08:04:10.394 +0000 INFO AdminManager - adding validation:savedsearch validation rule alert.suppress=validate( is_bool('alert.suppress'), "Value of argument 'alert.suppress' must be a boolean") ...
01-04-2013 08:04:10.394 +0000 INFO AdminManager - adding validation:savedsearch validation rule alert.suppress.period=validate ( match('alert.suppress.period', "(?i)^(ack)|(\d+[hmsd]?)$"), "Value of argument alert.suppress.period must be of the format [smhd]? or ack") ...
01-04-2013 08:04:10.399 +0000 INFO AdminManager - hId=/saved/searches, feedName=savedsearch, atomUrl=servicesNS/nbkbk7n/ecomm_splunk_env_monitoring
01-04-2013 08:04:22.241 +0000 INFO AdminManager - alias results: oldPath=/licenser/slaves, newPath=admin//slaves, handlerId=/licenser/slaves, tmpURL=/licenser
01-04-2013 08:04:22.241 +0000 ERROR AdminManager - Argument "timeout" is not supported by this handler.
01-04-2013 08:04:32.456 +0000 INFO AdminManager - alias results: oldPath=/server/info, newPath=admin//server-info, handlerId=/server/info, tmpURL=/server
01-04-2013 08:04:32.463 +0000 INFO AdminManager - hId=/server/info, feedName=server-info, atomUrl=services
01-04-2013 08:04:32.980 +0000 INFO AdminManager - alias results: oldPath=/server/info, newPath=admin//server-info, handlerId=/server/info, tmpURL=/server
01-04-2013 08:04:32.984 +0000 INFO AdminManager - hId=/server/info, feedName=server-info, atomUrl=services
01-04-2013 08:04:36.913 +0000 INFO AdminManager - alias results: oldPath=/saved/searches/DM%20missing%20sourcetypes/notify, newPath=admin//savedsearch/DM%20missing%20sourcetypes/notify, handlerId=/saved/searches, tmpURL=/saved
01-04-2013 08:04:36.915 +0000 INFO AdminManager - adding validation rules from restmap.conf [validation:savedsearch]


What does it mean and how can i fix this.

Anand

Tags (1)
1 Solution

MarioM
Motivator

it sounds like you have an incorrect value in Manager>>System configurations>>System settings>>General settings>>System timeout field

View solution in original post

0 Karma

MarioM
Motivator

it sounds like you have an incorrect value in Manager>>System configurations>>System settings>>General settings>>System timeout field

0 Karma

MarioM
Motivator

i am not sure as it doesnot seems to be linked to any of the above or below events...you might need to put log level to DEBUG for the AdminManager...

0 Karma

ma_anand1984
Contributor

Thank you Mario. 1h is the value i'm having. I ran AdminManager in info mode and have the following. Please see update in Question

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...