Getting Data In

How to resolve Splunk CIM errors and issues?

domino30
Path Finder

I am in a environment and I am able to get data in from a general perspective. We have a index clustered and search head clustered test  env  I can search *  and get data in andjust deal with that. we have the CIM vladiator app and we get  errors such as the following

cim validator error.PNG

cim validator.PNG

 So then I go and hunt the splunkd.log files of said location but really cant make heads or tails of whats important to solve any issues I may have.

attached are  the splukd.log from sh01 and indx03,indx03 and indx04 respectively.

splunk splunkd.log on SH01.PNG

splunkd.log from indx02.PNG

indx03.PNG

indx04.PNG

  Should I care about info warning and should I worry about warnings or should I focus on errors?

Keep in mind I have tried to search Some of these errors but they answers are amiguitous or not relevant or don't work.

 Is there a strategy that people use to go about this ?

is there anything that is seen on here that stands out?

Labels (2)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

It says that SA_CIM_validator cannot be found on the indexers. Is the app installed on them? Some apps need to be deployed on the indexers too, but not sure what else may be relevant or if that's necessary here.

Errno 111 = Connection Refused?

Can't offer much more I'm afraid.

 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Notice the spelling. The screenshot says "SA-cim_vladiator", not "validator".

There is much more going on underneath than meets the eye I'm afraid. Someone must have hurt this environment...

0 Karma

bowesmana
SplunkTrust
SplunkTrust
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Oh, my bad. Seemed like a typo more than a legitimate name.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...