Splunk Enterprise

Cannot find bid

jfaldmomacu
Path Finder

I'm getting thousands of log events that says --
ERROR CMSlave [2549383 CMNotifyThread] - Cannot find bid=wineventlog~157~96ECF7C4-1951-4288-B90A-9133E5408F14. cleaning up usage data

It is on all my indexers and references multiple but not all indexes. 

Any ideas on how to fix that error?

Labels (1)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust
What is your repFactor on indexes.conf file for those indexes?
And have you on multisite or single site cluster? And what are your RF + SF and site factors if you have multisite cluster?

View solution in original post

isoutamo
SplunkTrust
SplunkTrust

You should try to find another events which contains this bid from your _internal log. Those probably give you some hints what cause this error message.

0 Karma

jfaldmomacu
Path Finder

I picked a bid and searched for it. The only events are about its creation. Then the errors immediately start

2025-04-02 14_48_20-bidNotFound.png 
I checked three other bids with the same results. I even see messages about moving from hot to warm. ("Cleaning up usage" events excluded in these search results.)

2025-04-02 14_55_54-bidNotFound2.png

0 Karma

isoutamo
SplunkTrust
SplunkTrust
What is your repFactor on indexes.conf file for those indexes?
And have you on multisite or single site cluster? And what are your RF + SF and site factors if you have multisite cluster?

jfaldmomacu
Path Finder

I've seen the repFactor set to auto or 0. I'm changing all the non-internal indexes to auto, (adding the line repFactor to the stanzas that are missing them. 
RF and SF are 2.
I have a Single site cluster with 6 indexers. 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
In cluster you should also change internals to auto! Otherwise splunk don't replicate those buckets!

jfaldmomacu
Path Finder

But the ones that were missing the specified repFactor were the ones that had thousands of events. The other indexes that already had repFactor set to auto only had a few events with that error. So I think you may be on to something, 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...