Monitoring Splunk

Why am I seeing repeated LMDirective warnings in the splunkd.log and how to troubleshoot this?

sonicZ
Contributor

Noticing a number of warnings relating to LMDirective, not sure what these are related to and how to remedy.
Here's some samples

11-07-2014 00:06:21.461 +0000 WARN  LMDirective - directive cmd=D_set_feature_state args='Acceleration,ENABLED' failed: reason='feature='Acceleration' is invalid'
11-07-2014 00:06:21.461 +0000 WARN  LMDirective - directive cmd=D_set_feature_state args='AdvancedSearchCommands,ENABLED' failed: reason='feature='AdvancedSearchCommands' is invalid'
11-07-2014 00:06:21.461 +0000 WARN  LMDirective - directive cmd=D_set_feature_state args='AdvancedXML,ENABLED' failed: reason='feature='AdvancedXML' is invalid'
11-07-2014 00:06:21.461 +0000 WARN  LMDirective - directive cmd=D_set_feature_state args='CustomRoles,ENABLED' failed: reason='feature='CustomRoles' is invalid'
11-07-2014 00:06:21.461 +0000 WARN  LMDirective - directive cmd=D_set_feature_state args='GuestPass,ENABLED' failed: reason='feature='GuestPass' is invalid'
11-07-2014 00:06:21.461 +0000 WARN  LMDirective - directive cmd=D_set_feature_state args='KVStore,ENABLED' failed: reason='feature='KVStore' is invalid'
11-07-2014 00:06:21.461 +0000 WARN  LMDirective - directive cmd=D_set_feature_state args='LDAPAuth,ENABLED' failed: reason='feature='LDAPAuth' is invalid'
11-07-2014 00:06:21.462 +0000 WARN  LMDirective - directive cmd=D_set_feature_state args='MultisiteClustering,ENABLED' failed: reason='feature='MultisiteClustering' is invalid'
11-07-2014 00:06:21.462 +0000 WARN  LMDirective - directive cmd=D_set_feature_state args='NontableLookups,ENABLED' failed: reason='feature='NontableLookups' is invalid'
11-07-2014 00:06:21.462 +0000 WARN  LMDirective - directive cmd=D_set_feature_state args='RollingWindowAlerts,ENABLED' failed: reason='feature='RollingWindowAlerts' is invalid'
11-07-2014 00:06:21.462 +0000 WARN  LMDirective - directive cmd=D_set_feature_state args='ScheduledAlerts,ENABLED' failed: reason='feature='ScheduledAlerts' is invalid'
11-07-2014 00:06:21.462 +0000 WARN  LMDirective - directive cmd=D_set_feature_state args='ScheduledReports,ENABLED' failed: reason='feature='ScheduledReports' is invalid'
11-07-2014 00:06:21.462 +0000 WARN  LMDirective - directive cmd=D_set_feature_state args='SearchheadPooling,ENABLED' failed: reason='feature='SearchheadPooling' is invalid'
11-07-2014 00:06:21.462 +0000 WARN  LMDirective - directive cmd=D_set_feature_state args='UnisiteClustering,ENABLED' failed: reason='feature='UnisiteClustering' is invalid'
1 Solution

aaronkorn
Splunk Employee
Splunk Employee

This is a harmless message and is caused by mismatched versions of Splunk on the license server and peers. You can either update Splunk to the same versions or update the log level on each indexer with "./splunk set log-level LMDirective -level ERROR”

http://docs.splunk.com/Documentation/Splunk/6.2.1/ReleaseNotes/KnownIssues#Unsorted_issues - SPL-92831

View solution in original post

aaronkorn
Splunk Employee
Splunk Employee

This is a harmless message and is caused by mismatched versions of Splunk on the license server and peers. You can either update Splunk to the same versions or update the log level on each indexer with "./splunk set log-level LMDirective -level ERROR”

http://docs.splunk.com/Documentation/Splunk/6.2.1/ReleaseNotes/KnownIssues#Unsorted_issues - SPL-92831

hartfoml
Motivator

Thanks @aaronkorn this is the correct answer. this should be marked as answered.

0 Karma

twtmoore
Engager

This message popped up after I went from 6.1.1 to 6.20 across my internal splunk infrastructure.
My indexers, search head, deploy server, master are all 6.2.0.
My heavy forwarders are still a mix of 6.1.1, 6.1.5, and 6.2.0.
The heavy forwarders all report this error. It is really chatty.

0 Karma

eichfuss
Path Finder

Getting the same issue. But it is months ago, I upgraded the indexer and search head to 6.2 and now this problem comes up. Hope upgrading the heavy forwarders will solve the problem.

0 Karma

hartfoml
Motivator

I am getting this same issue. I think it has to do with the fact that some of my search heads are ant 6.2 and my indexers are not. this may be a feature that is not backwards compatible????

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...