Splunk Enterprise Security

Error message Failed to sync collection and investigations

zdrazil
New Member

I am getting below error message.

2019-07-11 09:36:25,643+0000 ERROR pid=18084 tid=MainThread file=configuration_check.py:run:228 | status="completed" task="confcheck_es_sync_investigation_xrefs" message="Failed to sync xref collection and investigations: Could not get investigation notable xrefs"

I have single-instance environment with fresh installation of Splunk Enterprise 7.2.7 and ES 5.3.0. I excluded all add-on during ES installation.

Can you please explain why this error message is coming and is there any impact on Splunk or ES?

thanks in advance for your reply
Michal

0 Karma

zdrazil
New Member

I've solved it. 🙂 It is not right solution. I've reinstalled Splunk and ES. The error is gone.

0 Karma

lakshman239
Influencer

Pls check the health of the kvstore and may need a restart again.

0 Karma

zdrazil
New Member

I've checked kvstore status by command:

./splunk show kvstore-status

Status is ready.

I am not sure how to check health of kvstore. You mean Monitoring console/Health check?

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...