Splunk Search

Error ProcessDispatchedSearch - PROCESS_SEARCH spamming splund logs

mookiie2005
Communicator

ERROR ProcessDispatchedSearch - PROCESS_SEARCH "XXX": The process cannot access the file because it is being used by another process.

we are getting these messages over and over 100's of times in the splunkd logs. We tried to clean out the dispatch directory and that has not had an impact. We just upgraded from Splunk version 5.0.3 to version 6.0.2.

mookiie2005
Communicator

I opened a splunk case for this issue. I was told that SPL-82288 version 6.0.6 will have a fix for this issue.

here is a temporary work around:

As a workaround, I suggest turning the log level of ProcessDispatchedSearch to CRITICAL or FATAL so that these "ERROR" level messages aren't displayed.
Note that the most serious problem here is just that splunkd.log gets polluted by all these messages which are supposed to be targeted to local search.log files. Basically, the search process is trying to open it's local /search.log, fails doing so, and therefore logs a message that is re-directed to splunkd because the local logging is not setup. We should just more or less ignore those re-directed messages.

slierninja
Communicator

Looks like this is fixed in 6.1.3 (SPL-82288)(SPL-84457)

0 Karma
Get Updates on the Splunk Community!

Good Sourcetype Naming

When it comes to getting data in, one of the earliest decisions made is what to use as a sourcetype. Often, ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Splunk App for Anomaly Detection End of Life Announcement

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...