Splunk IT Service Intelligence

Entity discovery failed to run. SAI internal logs. ?

arulnight
Explorer

Hi All,

I got message from Splunk dashboard that Entity discovery failed to run. SAI internal logs.

can anyone advise me on how to troubleshoot this issue ASAP?

arulnight
Explorer

Addtional info:

[root@IP]# tail -f collectd.log
[2019-09-10 19:01:33] [error] write splunk plugin: curl_easy_perform failed to connect to 10.100.64.196:8088 with status 7: Couldn't connect to server
[2019-09-10 19:02:03] [error] write splunk plugin: curl_easy_perform failed to connect to 10.100.64.196:8088 with status 7: Couldn't connect to server
[2019-09-10 19:11:38] [info] Exiting normally.
[2019-09-10 19:11:38] [info] collectd: Stopping 5 read threads.
[2019-09-10 19:11:38] [info] collectd: Stopping 5 write threads.
[2019-09-10 19:11:38] [warning] disk plugin: The "UdevNameAttr" option is only supported if collectd is built with libudev support
[2019-09-10 19:11:38] [info] Initialization complete, entering read-loop.
[2019-10-18 21:54:07] [info] Exiting normally.
[2019-10-18 21:54:07] [info] collectd: Stopping 5 read threads.
[2019-10-18 21:54:07] [info] collectd: Stopping 5 write threads.

anyone have any idea

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...