Splunk Search

Error ProcessDispatchedSearch - PROCESS_SEARCH spamming splund logs

mookiie2005
Communicator

ERROR ProcessDispatchedSearch - PROCESS_SEARCH "XXX": The process cannot access the file because it is being used by another process.

we are getting these messages over and over 100's of times in the splunkd logs. We tried to clean out the dispatch directory and that has not had an impact. We just upgraded from Splunk version 5.0.3 to version 6.0.2.

mookiie2005
Communicator

I opened a splunk case for this issue. I was told that SPL-82288 version 6.0.6 will have a fix for this issue.

here is a temporary work around:

As a workaround, I suggest turning the log level of ProcessDispatchedSearch to CRITICAL or FATAL so that these "ERROR" level messages aren't displayed.
Note that the most serious problem here is just that splunkd.log gets polluted by all these messages which are supposed to be targeted to local search.log files. Basically, the search process is trying to open it's local /search.log, fails doing so, and therefore logs a message that is re-directed to splunkd because the local logging is not setup. We should just more or less ignore those re-directed messages.

slierninja
Communicator

Looks like this is fixed in 6.1.3 (SPL-82288)(SPL-84457)

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...

Auto-Injector for Everything Else: Making OpenTelemetry Truly Universal

You might have seen Splunk’s recent announcement about donating the OpenTelemetry Injector to the ...