Splunk Search

Consistent error 500's on File and Directory new definitions

DaveSavage
Builder

Dear all,
Despite my newly rated karma status of 'new since 3 days ago' and '11' (gah ;-), I had been cruising at the heady heights of 40+ plus some badges having used Splunk and enjoyed this forum for about a year. This is my 1st question though, and I checked the answers beforehand, honest.
I'm seeing 500 Internal Server Error An error occurred while rendering the page template. See web_service.log.
When I attempt to define a new directory data source. The files sit on the indexer server, are all .txt files, appear ok in the config wizard even after my regex's.
The above log is pasted below:
%252Fdatainputstats&source=C%3A%5CWireshark_Logs%5C20121114&ns=search&breadcrumbs=Manager%7C%2Fmanager%09Data+inputs%7C%2Fmanager%2Fsearch%2Fdatainputstats, documentReferrer=http://192.168.0.85:8000/en-GB/custom/splunk_datapreview/steps?ns=search&breadcrumbs=&endpoint_base=..., flash=11.5.31, Splunk.Session.START_EVENT fired @Fri Nov 16 2012 13:29:44 GMT+0000 (GMT Standard Time)

2012-11-16 13:29:55,094 WARNING [50a63fd1c84a1cfd0] <string>:13 - get_formatter called on non-formattable object

quite a few of those...

2012-11-16 13:58:01,831 ERROR   [50a6466901322e470] admin:1120 - uiHelper processValueAdd operator failed for endpoint_path=data/inputs/monitor/_new elementName=spl-ctrl_sourcetypeSelect: list index out of range
2012-11-16 13:58:01,831 INFO    [50a6466901322e470] admin:1418 - Using override value from URL: def.spl-ctrl_EnableAdvanced=1
2012-11-16 13:58:01,831 INFO    [50a6466901322e470] admin:1418 - Using override value from URL: def.sourcetype=wireshark
2012-11-16 13:58:01,831 INFO    [50a6466901322e470] admin:1418 - Using override value from URL: def.name=C:\Wireshark_Logs\20121114
2012-11-16 13:58:01,831 INFO    [50a6466901322e470] admin:1418 - Using override value from URL: def.spl-ctrl_sourcetypeSelect=sourcetype

If anybody could direct me where to start looking, I'd be most appreciative.
Br
Dave
Splunk v5 Windows platform

Tags (1)
1 Solution

DaveSavage
Builder

Found it. Splunkd totally waterlogged, timeouts.
Good material in here also about saved searches. Not sure its v5 but the /var/run/splunk/dispatch folder is filling at a prodigious rate: rt_scheduler_admin_rt_scheduler__admin_RVFBTElTX0dQRzEz... folders.
Phew. Time for Friday...

View solution in original post

DaveSavage
Builder

Found it. Splunkd totally waterlogged, timeouts.
Good material in here also about saved searches. Not sure its v5 but the /var/run/splunk/dispatch folder is filling at a prodigious rate: rt_scheduler_admin_rt_scheduler__admin_RVFBTElTX0dQRzEz... folders.
Phew. Time for Friday...

Get Updates on the Splunk Community!

Splunk Edge Processor | Popular Use Cases to Get Started with Edge Processor

Splunk Edge Processor offers more efficient, flexible data transformation – helping you reduce noise, control ...

3 Ways to Make OpenTelemetry Even Better

My role as an Observability Specialist at Splunk provides me with the opportunity to work with customers of ...

What's New in Splunk Cloud Platform 9.2.2406?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2406 with many ...