Splunk Enterprise Security

Error message Failed to sync collection and investigations

zdrazil
New Member

I am getting below error message.

2019-07-11 09:36:25,643+0000 ERROR pid=18084 tid=MainThread file=configuration_check.py:run:228 | status="completed" task="confcheck_es_sync_investigation_xrefs" message="Failed to sync xref collection and investigations: Could not get investigation notable xrefs"

I have single-instance environment with fresh installation of Splunk Enterprise 7.2.7 and ES 5.3.0. I excluded all add-on during ES installation.

Can you please explain why this error message is coming and is there any impact on Splunk or ES?

thanks in advance for your reply
Michal

0 Karma

zdrazil
New Member

I've solved it. 🙂 It is not right solution. I've reinstalled Splunk and ES. The error is gone.

0 Karma

lakshman239
Influencer

Pls check the health of the kvstore and may need a restart again.

0 Karma

zdrazil
New Member

I've checked kvstore status by command:

./splunk show kvstore-status

Status is ready.

I am not sure how to check health of kvstore. You mean Monitoring console/Health check?

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...