Getting Data In

WARN CMHeartbeatThread what is this error telling me?

dkeck
Influencer

HI 🙂

I see a lot of these errors on one of my Clusterindexer, its an indexer with legacy data (not replicated in cluster).

Does anyone know what this is telling me? since I can´t find anything on answers or docs.

WARN  CMHeartbeatThread - event=SummaryRegistration got unknown_state for summary at path=$SPLUNK_DB/<index_name>/datamodel_summary/0_B8208014-CC0D-484A-8304-72E85F04F7AF/1DA71394-60C4-4788-BDEB-31F414XXXX/DM_Splunk_SA_CIM_XXXX.smlock.<indexer_name>-9298.temp-140536340007468

Sounds like the SH(1DA71394-60C4-4788-BDEB-31F414XXXX) is trying to run something on this indexer?!

Thank you 🙂

0 Karma

dxu_splunk
Splunk Employee
Splunk Employee

Its a no-op warning. The cluster will monitor for new summaries in the summary path (summaries are always folders). However, there are also temporary files in there (as the one listed above), that our code will log a WARNING against.

edit - is that file a folder btw? seems like we already guard against it in code...

0 Karma

dkeck
Influencer

Hi thank you for the answer.

I can´t answer the question, the file seems to be temporay, and its deleted pretty fast.

But I do see folders named like "DM_Splunk_SA_CIM_Authentication" with files like : done metadata_checksum metadata.csv

What can I do with these errors since there floding my splunkd.log I would like to get rid of them?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...