Monitoring Splunk

Why am I seeing repeated LMDirective warnings in the splunkd.log and how to troubleshoot this?

sonicZ
Contributor

Noticing a number of warnings relating to LMDirective, not sure what these are related to and how to remedy.
Here's some samples

11-07-2014 00:06:21.461 +0000 WARN  LMDirective - directive cmd=D_set_feature_state args='Acceleration,ENABLED' failed: reason='feature='Acceleration' is invalid'
11-07-2014 00:06:21.461 +0000 WARN  LMDirective - directive cmd=D_set_feature_state args='AdvancedSearchCommands,ENABLED' failed: reason='feature='AdvancedSearchCommands' is invalid'
11-07-2014 00:06:21.461 +0000 WARN  LMDirective - directive cmd=D_set_feature_state args='AdvancedXML,ENABLED' failed: reason='feature='AdvancedXML' is invalid'
11-07-2014 00:06:21.461 +0000 WARN  LMDirective - directive cmd=D_set_feature_state args='CustomRoles,ENABLED' failed: reason='feature='CustomRoles' is invalid'
11-07-2014 00:06:21.461 +0000 WARN  LMDirective - directive cmd=D_set_feature_state args='GuestPass,ENABLED' failed: reason='feature='GuestPass' is invalid'
11-07-2014 00:06:21.461 +0000 WARN  LMDirective - directive cmd=D_set_feature_state args='KVStore,ENABLED' failed: reason='feature='KVStore' is invalid'
11-07-2014 00:06:21.461 +0000 WARN  LMDirective - directive cmd=D_set_feature_state args='LDAPAuth,ENABLED' failed: reason='feature='LDAPAuth' is invalid'
11-07-2014 00:06:21.462 +0000 WARN  LMDirective - directive cmd=D_set_feature_state args='MultisiteClustering,ENABLED' failed: reason='feature='MultisiteClustering' is invalid'
11-07-2014 00:06:21.462 +0000 WARN  LMDirective - directive cmd=D_set_feature_state args='NontableLookups,ENABLED' failed: reason='feature='NontableLookups' is invalid'
11-07-2014 00:06:21.462 +0000 WARN  LMDirective - directive cmd=D_set_feature_state args='RollingWindowAlerts,ENABLED' failed: reason='feature='RollingWindowAlerts' is invalid'
11-07-2014 00:06:21.462 +0000 WARN  LMDirective - directive cmd=D_set_feature_state args='ScheduledAlerts,ENABLED' failed: reason='feature='ScheduledAlerts' is invalid'
11-07-2014 00:06:21.462 +0000 WARN  LMDirective - directive cmd=D_set_feature_state args='ScheduledReports,ENABLED' failed: reason='feature='ScheduledReports' is invalid'
11-07-2014 00:06:21.462 +0000 WARN  LMDirective - directive cmd=D_set_feature_state args='SearchheadPooling,ENABLED' failed: reason='feature='SearchheadPooling' is invalid'
11-07-2014 00:06:21.462 +0000 WARN  LMDirective - directive cmd=D_set_feature_state args='UnisiteClustering,ENABLED' failed: reason='feature='UnisiteClustering' is invalid'
1 Solution

aaronkorn
Splunk Employee
Splunk Employee

This is a harmless message and is caused by mismatched versions of Splunk on the license server and peers. You can either update Splunk to the same versions or update the log level on each indexer with "./splunk set log-level LMDirective -level ERROR”

http://docs.splunk.com/Documentation/Splunk/6.2.1/ReleaseNotes/KnownIssues#Unsorted_issues - SPL-92831

View solution in original post

aaronkorn
Splunk Employee
Splunk Employee

This is a harmless message and is caused by mismatched versions of Splunk on the license server and peers. You can either update Splunk to the same versions or update the log level on each indexer with "./splunk set log-level LMDirective -level ERROR”

http://docs.splunk.com/Documentation/Splunk/6.2.1/ReleaseNotes/KnownIssues#Unsorted_issues - SPL-92831

hartfoml
Motivator

Thanks @aaronkorn this is the correct answer. this should be marked as answered.

0 Karma

twtmoore
Engager

This message popped up after I went from 6.1.1 to 6.20 across my internal splunk infrastructure.
My indexers, search head, deploy server, master are all 6.2.0.
My heavy forwarders are still a mix of 6.1.1, 6.1.5, and 6.2.0.
The heavy forwarders all report this error. It is really chatty.

0 Karma

eichfuss
Path Finder

Getting the same issue. But it is months ago, I upgraded the indexer and search head to 6.2 and now this problem comes up. Hope upgrading the heavy forwarders will solve the problem.

0 Karma

hartfoml
Motivator

I am getting this same issue. I think it has to do with the fact that some of my search heads are ant 6.2 and my indexers are not. this may be a feature that is not backwards compatible????

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...