Splunk Enterprise Security

Enterprise Security script exited abnormally status="exited with code 3"

asimagu
Builder

hi gents,

we are getting the following error in our search heads. any ideas about what can be happening?
I already checked the swap memory and it seems fine. We are running version 4.5.1 of ES now and this did not happen with previous versions.

Error:
msg="A script exited abnormally" input="/export/gcs1/data/splunk/etc/apps/SA-Utils/bin/configuration_check.py" stanza="configuration_check://confcheck_reload_auth" status="exited with code 3"

gjanders
SplunkTrust
SplunkTrust

Please see my newest answer below, it's effectively a known issue in 4.7.0 and it will be fixed in 4.7.1 according to my support case.

0 Karma

rgaube
Explorer

Actually, I realize now that the stanza is a different one... "configuration_check://confcheck_es_app_version" and yes, we recently upgraded to v4.7.0.

0 Karma

gjanders
SplunkTrust
SplunkTrust

I upgraded to 4.7.x and found the same issue, the /opt/splunk/var/log/splunk/configuration_check.log or a similar log file should give you some hints...in my case I was importing apps that had been removed....once fixed the issue went away.

0 Karma

asimagu
Builder

ok, will do. This may take me some days as they still need to assign my user to the list of people who can open support cases from this company (I have been here for a few days only)

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...