Getting Data In

WARN CMHeartbeatThread what is this error telling me?

dkeck
Influencer

HI 🙂

I see a lot of these errors on one of my Clusterindexer, its an indexer with legacy data (not replicated in cluster).

Does anyone know what this is telling me? since I can´t find anything on answers or docs.

WARN  CMHeartbeatThread - event=SummaryRegistration got unknown_state for summary at path=$SPLUNK_DB/<index_name>/datamodel_summary/0_B8208014-CC0D-484A-8304-72E85F04F7AF/1DA71394-60C4-4788-BDEB-31F414XXXX/DM_Splunk_SA_CIM_XXXX.smlock.<indexer_name>-9298.temp-140536340007468

Sounds like the SH(1DA71394-60C4-4788-BDEB-31F414XXXX) is trying to run something on this indexer?!

Thank you 🙂

0 Karma

dxu_splunk
Splunk Employee
Splunk Employee

Its a no-op warning. The cluster will monitor for new summaries in the summary path (summaries are always folders). However, there are also temporary files in there (as the one listed above), that our code will log a WARNING against.

edit - is that file a folder btw? seems like we already guard against it in code...

0 Karma

dkeck
Influencer

Hi thank you for the answer.

I can´t answer the question, the file seems to be temporay, and its deleted pretty fast.

But I do see folders named like "DM_Splunk_SA_CIM_Authentication" with files like : done metadata_checksum metadata.csv

What can I do with these errors since there floding my splunkd.log I would like to get rid of them?

0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...