Getting Data In

Splunk index archiving to HDFS - throwing error "RollHandler - Could not find splunk_index"

devender_splunk
New Member

Though I can search index=digits from the search head, it's throwing the below message. Any clue on this?

2016-06-29 04:42:25.456 +0000 DEBUG UserGroupInformation$HadoopLoginModule - User entry: "dp_ed_p@YGRID.YAHOO.COM"
2016-06-29 04:42:25.457 +0000 INFO UserGroupInformation - Login successful for user dp_ed_p@YGRID.YAHOO.COM using keytab file /home/dp_ed_p/dp_ed_p.prod.headless.keytab
2016-06-29 04:42:25.458 +0000 INFO SplunkMR - Configured to use installed splunk package. Ensuring package exists
2016-06-29 04:42:25.463 +0000 INFO SplunkMR - Setting configuration to use local Splunk package: /home/dp_ed_p/splunk/splunk-6.4.1-debde650d26e-linux-2.6-x86_64.tgz
2016-06-29 04:42:25.487 +0000 WARN RollHandler - Could not find splunk_index=digits, ignoring ...
2016-06-29 04:42:25.487 +0000 DEBUG RollHandler - Done rolling buckets to virtual_index=digits_archive
0 Karma

kpawar_splunk
Splunk Employee
Splunk Employee

"Could not find splunk_index=digits" warning is thrown when index digits does not exist. Since you can search index on SH, index does exist on SH.
Do you have distributed deployment with one or more indexers or indexer cluster. Archiving tries to archive data on SH and indexers. Most likely one of your indexer does not have index digits. This message could be coming from that indexer.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...