Splunk Search

Consistent error 500's on File and Directory new definitions

DaveSavage
Builder

Dear all,
Despite my newly rated karma status of 'new since 3 days ago' and '11' (gah ;-), I had been cruising at the heady heights of 40+ plus some badges having used Splunk and enjoyed this forum for about a year. This is my 1st question though, and I checked the answers beforehand, honest.
I'm seeing 500 Internal Server Error An error occurred while rendering the page template. See web_service.log.
When I attempt to define a new directory data source. The files sit on the indexer server, are all .txt files, appear ok in the config wizard even after my regex's.
The above log is pasted below:
%252Fdatainputstats&source=C%3A%5CWireshark_Logs%5C20121114&ns=search&breadcrumbs=Manager%7C%2Fmanager%09Data+inputs%7C%2Fmanager%2Fsearch%2Fdatainputstats, documentReferrer=http://192.168.0.85:8000/en-GB/custom/splunk_datapreview/steps?ns=search&breadcrumbs=&endpoint_base=..., flash=11.5.31, Splunk.Session.START_EVENT fired @Fri Nov 16 2012 13:29:44 GMT+0000 (GMT Standard Time)

2012-11-16 13:29:55,094 WARNING [50a63fd1c84a1cfd0] <string>:13 - get_formatter called on non-formattable object

quite a few of those...

2012-11-16 13:58:01,831 ERROR   [50a6466901322e470] admin:1120 - uiHelper processValueAdd operator failed for endpoint_path=data/inputs/monitor/_new elementName=spl-ctrl_sourcetypeSelect: list index out of range
2012-11-16 13:58:01,831 INFO    [50a6466901322e470] admin:1418 - Using override value from URL: def.spl-ctrl_EnableAdvanced=1
2012-11-16 13:58:01,831 INFO    [50a6466901322e470] admin:1418 - Using override value from URL: def.sourcetype=wireshark
2012-11-16 13:58:01,831 INFO    [50a6466901322e470] admin:1418 - Using override value from URL: def.name=C:\Wireshark_Logs\20121114
2012-11-16 13:58:01,831 INFO    [50a6466901322e470] admin:1418 - Using override value from URL: def.spl-ctrl_sourcetypeSelect=sourcetype

If anybody could direct me where to start looking, I'd be most appreciative.
Br
Dave
Splunk v5 Windows platform

Tags (1)
1 Solution

DaveSavage
Builder

Found it. Splunkd totally waterlogged, timeouts.
Good material in here also about saved searches. Not sure its v5 but the /var/run/splunk/dispatch folder is filling at a prodigious rate: rt_scheduler_admin_rt_scheduler__admin_RVFBTElTX0dQRzEz... folders.
Phew. Time for Friday...

View solution in original post

DaveSavage
Builder

Found it. Splunkd totally waterlogged, timeouts.
Good material in here also about saved searches. Not sure its v5 but the /var/run/splunk/dispatch folder is filling at a prodigious rate: rt_scheduler_admin_rt_scheduler__admin_RVFBTElTX0dQRzEz... folders.
Phew. Time for Friday...

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...