Monitoring Splunk

Why receiving resource usage errors in splunkd.log "Failure getting value for disk reads"

kksol007
Engager

Every minute log this message.
I want to know cause of error message and know workaround.

02-27-2017 17:55:04.455 +0900 WARN IntrospectionGenerator:resource_usage - RU - Failure getting value for disk reads ((D:)), status code is -1073738810

追記:
日本語でも質問できるようなので、japaneseタグを追加

maraman_splunk
Splunk Employee
Splunk Employee

Hi,

you are probably running splunk as non root on a hardened linux
your splunk user doesn't have right to collect these stats....

0 Karma

yujietay
Path Finder

Hi maraman,

I am also getting the same error, but I'm running my Splunk instances (specifically happens only on indexers) on Windows.

I've already assigned permissions to the disk but to no avail.

0 Karma

Motoko89
Path Finder

I am seeing the same in Windows as well. How do I fix it?

0 Karma
Get Updates on the Splunk Community!

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...