Hello Friends,
I am consistently receiving alerts that the README file found in the path /opt/splunk/etc/system/lookups/ within my SHC is missing. When hit that directory I can confirm that it is gone, and while I believe it to be a default file, when I take a copy of it from another instance that has no issue, the file is removed after 5 or so minutes. I have confirmed that file owner and group are splunk and while the file is present, I can cat it without issue.
Would anyone have seen this themselves or have any ideas on how to remediate it? Thank you.
Could you please check if anyone accidentally put a system app inside the shcluster/apps/ folder? Also, can you see if there are any local scripts or jobs that might be cleaning up or removing files from the lookup folder?
Also anything from splunk _internal logs?
Regards,
Prewin
If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!
There is an automation that is supposed to only grab CSV files and move them into another directory. Looks like it needs to be tweaked because it is also grabbing text files. Appreciate the help.
Could you please check if anyone accidentally put a system app inside the shcluster/apps/ folder? Also, can you see if there are any local scripts or jobs that might be cleaning up or removing files from the lookup folder?
Also anything from splunk _internal logs?
Regards,
Prewin
If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!