I am in a environment and I am able to get data in from a general perspective. We have a index clustered and search head clustered test env I can search * and get data in andjust deal with that. we have the CIM vladiator app and we get errors such as the following
So then I go and hunt the splunkd.log files of said location but really cant make heads or tails of whats important to solve any issues I may have.
attached are the splukd.log from sh01 and indx03,indx03 and indx04 respectively.
Should I care about info warning and should I worry about warnings or should I focus on errors?
Keep in mind I have tried to search Some of these errors but they answers are amiguitous or not relevant or don't work.
Is there a strategy that people use to go about this ?
is there anything that is seen on here that stands out?
It says that SA_CIM_validator cannot be found on the indexers. Is the app installed on them? Some apps need to be deployed on the indexers too, but not sure what else may be relevant or if that's necessary here.
Errno 111 = Connection Refused?
Can't offer much more I'm afraid.
Notice the spelling. The screenshot says "SA-cim_vladiator", not "validator".
There is much more going on underneath than meets the eye I'm afraid. Someone must have hurt this environment...
Oh, my bad. Seemed like a typo more than a legitimate name.