Getting Data In

How to resolve Splunk CIM errors and issues?

domino30
Path Finder

I am in a environment and I am able to get data in from a general perspective. We have a index clustered and search head clustered test  env  I can search *  and get data in andjust deal with that. we have the CIM vladiator app and we get  errors such as the following

cim validator error.PNG

cim validator.PNG

 So then I go and hunt the splunkd.log files of said location but really cant make heads or tails of whats important to solve any issues I may have.

attached are  the splukd.log from sh01 and indx03,indx03 and indx04 respectively.

splunk splunkd.log on SH01.PNG

splunkd.log from indx02.PNG

indx03.PNG

indx04.PNG

  Should I care about info warning and should I worry about warnings or should I focus on errors?

Keep in mind I have tried to search Some of these errors but they answers are amiguitous or not relevant or don't work.

 Is there a strategy that people use to go about this ?

is there anything that is seen on here that stands out?

Labels (2)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

It says that SA_CIM_validator cannot be found on the indexers. Is the app installed on them? Some apps need to be deployed on the indexers too, but not sure what else may be relevant or if that's necessary here.

Errno 111 = Connection Refused?

Can't offer much more I'm afraid.

 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Notice the spelling. The screenshot says "SA-cim_vladiator", not "validator".

There is much more going on underneath than meets the eye I'm afraid. Someone must have hurt this environment...

0 Karma

bowesmana
SplunkTrust
SplunkTrust
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Oh, my bad. Seemed like a typo more than a legitimate name.

0 Karma
Get Updates on the Splunk Community!

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Automatic Discovery Part 2: Setup and Best Practices

In Part 1 of this series, we covered what Automatic Discovery is and why it’s critical for observability at ...