Splunk Enterprise

Error in search head pooling validate: Failed to lock

mkelderm
Path Finder

Any idea why we have this error?

splunk pooling validate
ERROR SearchHeadPoolInfo - Error reading search head pool info: Failed to lock /data/splunk/etc/pooling/pooling.ini with code -1, possible reason: No such file or directory
Error in search head pooling validate: Failed to lock /data/splunk/etc/users/testpath with code -1, possible reason: Success

We have 2 search heads (linux 64bit). One SH is sharing via Samba, the other SH is mapping to this directory

Splunk is working normally...Only during startup/shutdown and validate commands we see this error.

Any ideas?

Marc+++++++++++++++++++++++++++++++++++++++

Tags (2)

_d_
Splunk Employee
Splunk Employee

I would just delete pooling.ini.SearchHeadName and pool.ini.lock files. It's possible that one of the search heads did not properly remove its lock so the other members of the pool fail to validate - and therefore fail to acquire a lock quickly - but still service the search after a certain timeout threshold. And a corollary of this is that your searches' runtime may be unnecessarily padded.

0 Karma

mkelderm
Path Finder

I did, but the issue still exisis

0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.