Getting Data In

WinEventLogChannel - saveCheckpointStr : Unable to write checkpoint with a null string

dmlee
Communicator

Hi, there are lots of ERROR messages in splunkd.log (version 4.2.3 , play as LightForwarder)

and this Splunk LWF send all of the WinEventLog to indexer again and again , so there are many duplicate events in indexer.

09-20-2011 12:15:49.744 +0800 ERROR WinEventLogChannel - saveCheckpointStr: Unable to write checkpoint with a null string
09-20-2011 12:15:49.744 +0800 ERROR WinEventLogChannel - WELCheckPoint::save: Failed to save checkpoint file='': 操作順利完成(success)。
09-20-2011 12:15:49.837 +0800 ERROR WinEventLogChannel - saveCheckpointStr: Failed to rename checkpoint file '.tmp' -> '': 系統找不到指定的路徑(can't find the path)


any idea about it? thanks

Tags (1)
1 Solution

jrodman
Splunk Employee
Splunk Employee

Clearly this was a defect. Given how much code in the WinEventLog input in general, and the checkpointing in specific, it is nearly impossible that this bug still exists. (Though if this class of problem arises please do contact support.)

View solution in original post

0 Karma

jrodman
Splunk Employee
Splunk Employee

Clearly this was a defect. Given how much code in the WinEventLog input in general, and the checkpointing in specific, it is nearly impossible that this bug still exists. (Though if this class of problem arises please do contact support.)

0 Karma

jumper4000
Explorer

I'm having the same issue. Any help would be appreciated.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...