Splunk Dev

Could not read event: cd=(n/a). Results may be incomplete !

LordLeet
Path Finder

Hello,

I'm experiencing this error when I perform some searches on my index,
idx= Could not read event: cd=(n/a). Results may be incomplete ! (logging only the first such error; enable DEBUG to see the rest)

I saw this issue was fixed on 7.0.1 but my instances are on 6.4.8, is there a workaround for this or a way to fix it?

I tried these commands:

splunk fsck scan --all-buckets-all-indexes
splunk fsck repair --all-buckets-all-indexes

But it with no success.

Thanks in advance

dd_msearles
Path Finder

Did you ever get a resolution to this?
I have been getting the same errors when querying some indexes over long periods of time.

I believe we have corrupt buckets, potentially as a result of a stray fsck.
During routine inspeciton of the Indexers I recall seeing a couple of fsck processes not as a child process of splunkd - which seemed very odd.

Running 7.00 - due to upgade to 7.01+ shortly.,

0 Karma

LordLeet
Path Finder

Hey dd_msearles,

The issue solved itself since the events causing the issue were removed due to my retention time period.

Sorry for not being of great help.

Regards

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...