Security

Seeing errors related to Unix (*NIX) app's interfaces.sh

asleeis
Path Finder

Anyone know what this is? When I run the interfaces.sh script manually, I do not get any errors. But I'm seeing current and regular errors when looking at the "_internal" index for "ERROR" log_level.

"could not lookup DNS configuration info service: (ipc/send) invalid destination port"

That's the error message... pretty much 2 every minute.

Anyone know what this is and how to stop it. I don't know what this may be affecting in the reports, etc. But things seem to work. Not entirely sure. But I don't like seeing errors in stuff.

Thanks, -Alex

Tags (1)
0 Karma

rcarragher
New Member

Did anyone move past this? I'm on Mac OSX Server 10.6.8 and having the same exact problem as described above.

0 Karma

V_at_Splunk
Splunk Employee
Splunk Employee

Alex, please file a support issue, and provide the following information:

  • UNIX flavor (little birdie tells me it's Mac OS X), and version (on Mac, find with sw_vers).
  • does error happen if you run script in background? in background in a loop? I.e., for dummy in /usr/bin/*; do /v-p4/current/cfg/bundles/unix/bin/interfaces.sh; done &
  • run script with --debug option; a file like debug--interfaces.sh--Fri_Jan__7_16-08-14_PST_2011 will appear in directory where script is found. Please attach this file.
  • tell them to assign issue to Vainstein

Thank you.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Automated Threat Analysis: Available in ES Premier

Automated Threat Analysis: Centralize and Accelerate Phishing Investigations in Splunk Enterprise ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...