I am running splunk 6.0.2 on OS X 10.7.5 The serach head, indexer are all installed on the same box.
I added the /var/log
directory as well as /var/log/system.log
file separately to be indexed.
Both the above indexed fine however after a splunk restart, I am getting the following error in web_service.log
2014-03-06 07:44:25,317
ERROR [531889c8b91086a0590] eai:164 -
Failed to fetch dynamic element
content from the server for
splunkSource:/search/jobs/oneshot
[HTTP 204] Unexpected HTTP status code
This corresponds to the following error in Splunk Web:
Data inputs>>Files & Directories>>/var/log>>Index
Failed to fetch data: Unexpected HTTP status code.
I tried to create a new index but this has not solved the issue. I have also restarted splunk, both from the cli and Splunk Web.
This issue was fixed by uninstalling Splunk 6.0.2 and installing 6.0.1 instead.
There appear to be some bugs in the install dmg for 6.0.2:
splunk-6.0.2-196940-macosx-10.7-intel.dmg
This issue was fixed by uninstalling Splunk 6.0.2 and installing 6.0.1 instead.
There appear to be some bugs in the install dmg for 6.0.2:
splunk-6.0.2-196940-macosx-10.7-intel.dmg