splunk pooling validate
ERROR SearchHeadPoolInfo - Error reading search head pool info: Failed to lock /data/splunk/etc/pooling/pooling.ini with code -1, possible reason: No such file or directory
Error in search head pooling validate: Failed to lock /data/splunk/etc/users/testpath with code -1, possible reason: Success
We have 2 search heads (linux 64bit). One SH is sharing via Samba, the other SH is mapping to this directory
Splunk is working normally...Only during startup/shutdown and validate commands we see this error.
I would just delete pooling.ini.SearchHeadName and pool.ini.lock files. It's possible that one of the search heads did not properly remove its lock so the other members of the pool fail to validate - and therefore fail to acquire a lock quickly - but still service the search after a certain timeout threshold. And a corollary of this is that your searches' runtime may be unnecessarily padded.