Splunk Search

Error ProcessDispatchedSearch - PROCESS_SEARCH spamming splund logs

mookiie2005
Communicator

ERROR ProcessDispatchedSearch - PROCESS_SEARCH "XXX": The process cannot access the file because it is being used by another process.

we are getting these messages over and over 100's of times in the splunkd logs. We tried to clean out the dispatch directory and that has not had an impact. We just upgraded from Splunk version 5.0.3 to version 6.0.2.

mookiie2005
Communicator

I opened a splunk case for this issue. I was told that SPL-82288 version 6.0.6 will have a fix for this issue.

here is a temporary work around:

As a workaround, I suggest turning the log level of ProcessDispatchedSearch to CRITICAL or FATAL so that these "ERROR" level messages aren't displayed.
Note that the most serious problem here is just that splunkd.log gets polluted by all these messages which are supposed to be targeted to local search.log files. Basically, the search process is trying to open it's local /search.log, fails doing so, and therefore logs a message that is re-directed to splunkd because the local logging is not setup. We should just more or less ignore those re-directed messages.

slierninja
Communicator

Looks like this is fixed in 6.1.3 (SPL-82288)(SPL-84457)

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Meet Splunk Observability Studio: AI-Assisted OpenTelemetry Instrumentation Without ...

Instrumentation is usually the last step or even an afterthought when building out a project. The feature ...

Federated Search for Cisco Security and Analytics Logging (SAL) is now GA on Splunk ...

Federated Search for Cisco  Security Analytics and Logging (SAL) is now generally available as part of the ...

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner   Join us for a demo-driven look at how ...