Getting Data In

WinEventLogChannel - saveCheckpointStr : Unable to write checkpoint with a null string

dmlee
Communicator

Hi, there are lots of ERROR messages in splunkd.log (version 4.2.3 , play as LightForwarder)

and this Splunk LWF send all of the WinEventLog to indexer again and again , so there are many duplicate events in indexer.

09-20-2011 12:15:49.744 +0800 ERROR WinEventLogChannel - saveCheckpointStr: Unable to write checkpoint with a null string
09-20-2011 12:15:49.744 +0800 ERROR WinEventLogChannel - WELCheckPoint::save: Failed to save checkpoint file='': 操作順利完成(success)。
09-20-2011 12:15:49.837 +0800 ERROR WinEventLogChannel - saveCheckpointStr: Failed to rename checkpoint file '.tmp' -> '': 系統找不到指定的路徑(can't find the path)


any idea about it? thanks

Tags (1)
1 Solution

jrodman
Splunk Employee
Splunk Employee

Clearly this was a defect. Given how much code in the WinEventLog input in general, and the checkpointing in specific, it is nearly impossible that this bug still exists. (Though if this class of problem arises please do contact support.)

View solution in original post

0 Karma

jrodman
Splunk Employee
Splunk Employee

Clearly this was a defect. Given how much code in the WinEventLog input in general, and the checkpointing in specific, it is nearly impossible that this bug still exists. (Though if this class of problem arises please do contact support.)

0 Karma

jumper4000
Explorer

I'm having the same issue. Any help would be appreciated.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...