Security

Why do we get the exited with code 255 error for each indexer?

danielbb
Motivator

When running | datamodel Intrusion_Detection search I get the following error message for each indexer -

[<indexer name>] Search process did not exit cleanly, exit_code=255, description="exited with code 255". Please look in search.log for this peer in the Job Inspector for more info. 

What can it be?

Tags (1)
0 Karma

MuS
SplunkTrust
SplunkTrust

Hi danielbb,

check the OS logs of your indexer, one of the reasons for this can be that your search job was killed by OOM (Out of Memory) Killer .. assuming you are running the indexers on nix.

cheers, MuS

danielbb
Motivator

@MuS, I've been working with Support on that and we found out that all the indexers throw the following error -

-- 10-16-2019 16:03:39.534 ERROR SearchParser - The search specifies a macro varonis_index that cannot be found. Reasons include: the macro name is misspelled, you do not have "read" permission for the macro, or the macro has not been shared with this application. Click Settings, Advanced search, Search Macros to view macro information.

We also saw that when running index=_internal, we see the same error (many times), but in the case of index=_internal, this error doesn't prevent the command from completing its work and display the results.

A similar thread at ERROR SearchParser - The search specifies a macro 'cs_get_index' that cannot be found.

0 Karma

danielbb
Motivator

Support is saying that every search I submit is checked against my eventtype.confs

0 Karma

danielbb
Motivator
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...