Monitoring Splunk

Error STmgr - dir unexpected

MUmair_DOI
Engager

I have two IDX pointed to a SH a couple of weeks an error started flooding in from Splunkd. It looks to be for metrics.log file, but I cannot seem understand what the error is and have not been able to figure out a solution by searching the community forums. 

Essentially, the following errors continue to come in about 1000 errors an hour or so. It was only coming from 1 IDX at first, but now its coming from bother IDXs. 

Sample errors:

 

01-25-2021 16:50:16.946 +0000 ERROR STMgr - dir='/opt/splunk/var/lib/splunk/_metrics/db/hot_v1_49' unexpected rc=-104 (kw= sourcetype::splunk_metrics_log, len=31) warm_rc[0,2] from st_txn_put

01-25-2021 16:50:16.946 +0000 ERROR STMgr - dir='/opt/splunk/var/lib/splunk/_metrics/db/hot_v1_49' unexpected rc=-104 (kw= host::iinabqlvtsplidx2, len=23) warm_rc[0,2] from st_txn_put

01-25-2021 16:50:16.946 +0000 ERROR STMgr - dir='/opt/splunk/var/lib/splunk/_metrics/db/hot_v1_49' unexpected rc=-104 (kw= source::/opt/splunk/var/log/introspection/kvstore.log, len=54) warm_rc[0,2] from st_txn_put

01-25-2021 16:50:16.946 +0000 ERROR STMgr - dir='/opt/splunk/var/lib/splunk/_metrics/db/hot_v1_49' unexpected rc=-104 (kw=_catalog::spl.mlog.nullgroup.data.metrics.commands._mergeAuthzCollections.total|CN|O|component|data.$clusterTime.signature.hash.$binary|data.extra_info.note|data.host|data.mem.supported|data.metrics.repl.executor.networkInterface|data.metrics.repl.executor.shuttingDown|data.network.serviceExecutorTaskStats.executor|data.process|data.repl.electionId.$oid|data.repl.hosts|data.repl.ismaster|data.repl.me|data.repl.primary|data.repl.secondary|data.repl.setName|data.repl.tags.all|data.repl.tags.instance|data.security.SSLServerHasCertificateAuthority|data.security.SSLServerSubjectName|data.storageEngine.name|data.storageEngine.persistent|data.storageEngine.readOnly|data.storageEngine.supportsCommittedReads|data.tcmalloc.tcmalloc.formattedString|data.version|datetime|log_level, len=779) warm_rc[0,2] from st_txn_put

01-25-2021 16:50:16.946 +0000 ERROR STMgr - dir='/opt/splunk/var/lib/splunk/_metrics/db/hot_v1_49' unexpected rc=-104 (kw=_catalog::spl.mlog.nullgroup.data.globalLock.currentQueue.total|CN|O|component|data.$clusterTime.signature.hash.$binary|data.extra_info.note|data.host|data.mem.supported|data.metrics.repl.executor.networkInterface|data.metrics.repl.executor.shuttingDown|data.network.serviceExecutorTaskStats.executor|data.process|data.repl.electionId.$oid|data.repl.hosts|data.repl.ismaster|data.repl.me|data.repl.primary|data.repl.secondary|data.repl.setName|data.repl.tags.all|data.repl.tags.instance|data.security.SSLServerHasCertificateAuthority|data.security.SSLServerSubjectName|data.storageEngine.name|data.storageEngine.persistent|data.storageEngine.readOnly|data.storageEngine.supportsCommittedReads|data.tcmalloc.tcmalloc.formattedString|data.version|datetime|log_level, len=763) warm_rc[0,2] from st_txn_put

 


Basically the same error are repeating over and over again in a similar fasion.

 

Labels (3)

AlvaroFernandez
Engager

Same here since the migration to v8.0.9. 

No solution found so far

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...