Getting Data In

How to resolve Splunk CIM errors and issues?

domino30
Path Finder

I am in a environment and I am able to get data in from a general perspective. We have a index clustered and search head clustered test  env  I can search *  and get data in andjust deal with that. we have the CIM vladiator app and we get  errors such as the following

cim validator error.PNG

cim validator.PNG

 So then I go and hunt the splunkd.log files of said location but really cant make heads or tails of whats important to solve any issues I may have.

attached are  the splukd.log from sh01 and indx03,indx03 and indx04 respectively.

splunk splunkd.log on SH01.PNG

splunkd.log from indx02.PNG

indx03.PNG

indx04.PNG

  Should I care about info warning and should I worry about warnings or should I focus on errors?

Keep in mind I have tried to search Some of these errors but they answers are amiguitous or not relevant or don't work.

 Is there a strategy that people use to go about this ?

is there anything that is seen on here that stands out?

Labels (2)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

It says that SA_CIM_validator cannot be found on the indexers. Is the app installed on them? Some apps need to be deployed on the indexers too, but not sure what else may be relevant or if that's necessary here.

Errno 111 = Connection Refused?

Can't offer much more I'm afraid.

 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Notice the spelling. The screenshot says "SA-cim_vladiator", not "validator".

There is much more going on underneath than meets the eye I'm afraid. Someone must have hurt this environment...

0 Karma

bowesmana
SplunkTrust
SplunkTrust
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Oh, my bad. Seemed like a typo more than a legitimate name.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...