Splunk Enterprise

Help with Failed to remove alive token Error

kgellis
Engager
 

 

i have noticed this error coming up often and have searched everywhere to find out what it is and if there is a fix for it.

09-29-2021 05:41:07.533 -0500 ERROR ScopedAliveProcessToken [2371353 BundleLookupIndexingExecutorWorker-0] - Failed to remove alive token file='/opt/splunk/var/run/searchpeers/DFADFAB9-11E6-4297-97DF-9227BFECA4AE-1632912055/apps/live_edge/lookups/LiveEdge_FatalLogs.csv_1632911454.870215.cs.index.lock'. No such file or directory

source = /opt/splunk/var/log/splunk/splunkd.log
sourcetype = splunkd

 

Labels (1)

kgellis
Engager

Still Searching for a solution and or root cause.  so far we just have to flag as known error and check in time to time to see if anyone else may have come up with a different idea.  but the files are gone as the error states as if the process completed but it still tracking the file and attempts to remove it again? 

0 Karma

Zzo911
Engager

Did you find a fix for that?

0 Karma

diogofgm
SplunkTrust
SplunkTrust

Can check in the box if the file actually exists and check the permissions?

------------
Hope I was able to help you. If so, some karma would be appreciated.
0 Karma

dm1
Contributor

facing same issue. were you able to fix this ?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...