Getting Data In

WinEventLogChannel - saveCheckpointStr : Unable to write checkpoint with a null string

dmlee
Communicator

Hi, there are lots of ERROR messages in splunkd.log (version 4.2.3 , play as LightForwarder)

and this Splunk LWF send all of the WinEventLog to indexer again and again , so there are many duplicate events in indexer.

09-20-2011 12:15:49.744 +0800 ERROR WinEventLogChannel - saveCheckpointStr: Unable to write checkpoint with a null string
09-20-2011 12:15:49.744 +0800 ERROR WinEventLogChannel - WELCheckPoint::save: Failed to save checkpoint file='': 操作順利完成(success)。
09-20-2011 12:15:49.837 +0800 ERROR WinEventLogChannel - saveCheckpointStr: Failed to rename checkpoint file '.tmp' -> '': 系統找不到指定的路徑(can't find the path)


any idea about it? thanks

Tags (1)
1 Solution

jrodman
Splunk Employee
Splunk Employee

Clearly this was a defect. Given how much code in the WinEventLog input in general, and the checkpointing in specific, it is nearly impossible that this bug still exists. (Though if this class of problem arises please do contact support.)

View solution in original post

0 Karma

jrodman
Splunk Employee
Splunk Employee

Clearly this was a defect. Given how much code in the WinEventLog input in general, and the checkpointing in specific, it is nearly impossible that this bug still exists. (Though if this class of problem arises please do contact support.)

0 Karma

jumper4000
Explorer

I'm having the same issue. Any help would be appreciated.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...