Getting Data In

splunkd.log error : GetInt64Val: ldap_get_values error

CSabhaya
Engager

I am constantly getting the following message from splunk forwarder splunkd.log

03-17-2014 11:38:28.245 -0700 WARN ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"" splunk-regmon - SysmonMigrator::read - 'sysmon.conf' was not found, no migration is required.
03-17-2014 11:58:32.247 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::GetInt64Val: ldap_get_values error
03-17-2014 11:58:32.247 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.
03-17-2014 11:58:32.247 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::GetInt64Val: ldap_get_values error
03-17-2014 11:58:32.247 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.
03-17-2014 12:01:17.610 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::GetInt64Val: ldap_get_values error
03-17-2014 12:01:17.610 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.
03-17-2014 12:12:15.646 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::GetInt64Val: ldap_get_values error
03-17-2014 12:12:15.646 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.
03-17-2014 12:15:01.594 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::GetInt64Val: ldap_get_values error
03-17-2014 12:15:01.594 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.
03-17-2014 12:15:01.594 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::GetInt64Val: ldap_get_values error
03-17-2014 12:15:01.594 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.
03-17-2014 12:16:33.793 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::GetInt64Val: ldap_get_values error
03-17-2014 12:16:33.793 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.
03-17-2014 12:18:02.373 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::GetInt64Val: ldap_get_values error
03-17-2014 12:18:02.373 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.
03-17-2014 12:18:02.373 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::GetInt64Val: ldap_get_values error
03-17-2014 12:18:02.373 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.
03-17-2014 12:20:46.566 -0700 INFO WatchedFile - Logfile truncated while open, original pathname file='C:\Users\rq113d\Desktop\test1\IVTRUpdateLog_2014-03-16 20-101.txt', will begin reading from start.
03-17-2014 12:24:25.501 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::GetInt64Val: ldap_get_values error
03-17-2014 12:24:25.501 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.
03-17-2014 12:24:25.501 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::GetInt64Val: ldap_get_values error
03-17-2014 12:24:25.501 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.
03-17-2014 12:39:50.170 -0700 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"" splunk-admon - AdQuery::GetInt64Val: ldap_get_values error

Is anyone having similar issue? what this error indicates. Any suggestions?

e2eadmin
Explorer

Was there ever an answer to this? I am having the same problem. Thanks.

0 Karma

ccraft_splunk
Splunk Employee
Splunk Employee

Has there been answer found out for this? I am having the same problem?

0 Karma

stefan1988
Path Finder

I'm getting the same message

0 Karma

davidboose
Engager

bump

we are too

0 Karma

adhoke_splunk
Splunk Employee
Splunk Employee

can you check inputs.conf and admon.conf to see that stanzas not configured by you are set to 'disabled=1'

This error shows up because Active Directory query is not returning required values.

0 Karma

ankeetashet
Engager

We are facing a similar issue as well. We are trying to read windows event logs from a machine which has a Splunk forwarder installed version 5.0.1. The inputs.conf file is as below:

[WinEventLog://Application]
checkpointInterval = 5
current_only = 0
disabled = 0
index = mag_nprod
start_from = oldest

[WinEventLog://System]
checkpointInterval = 5
current_only = 0
disabled = 0
index = mag_nprod
start_from = oldest

The following error message is present in the Splunkd logs:

10-09-2014 15:47:22.660 +0100 ERROR ExecProcessor - message from "E:\tools\SplunkForwarder\bin\splunk-admon.exe" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.
10-09-2014 15:47:22.660 +0100 ERROR ExecProcessor - message from "E:\tools\SplunkForwarder\bin\splunk-admon.exe" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.
10-09-2014 15:47:19.034 +0100 ERROR ExecProcessor - message from "E:\tools\SplunkForwarder\bin\splunk-admon.exe" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.
10-09-2014 15:47:18.409 +0100 ERROR ExecProcessor - message from "E:\tools\SplunkForwarder\bin\splunk-admon.exe" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.
10-09-2014 15:46:51.783 +0100 ERROR ExecProcessor - message from "E:\tools\SplunkForwarder\bin\splunk-admon.exe" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.
10-09-2014 15:46:27.158 +0100 ERROR ExecProcessor - message from "E:\tools\SplunkForwarder\bin\splunk-admon.exe" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.

Any suggestions please?

season88481
Contributor

I got this error as well:

10-09-2014 15:46:27.158 +0100 ERROR ExecProcessor - message from "E:\tools\SplunkForwarder\bin\splunk-admon.exe" splunk-admon - AdQuery::ProcessMessage: Cannot get uSNChanged from message.

Had checked the \bin directory, the splunk-admon.exe is not missing.

Not sure what to do next though.

0 Karma
Get Updates on the Splunk Community!

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...