Splunk Search

Getting errors for every search I run

usha_nittala
New Member

Hi All,

I am getting below error for every search I am rinning for Summary indexing.

Search process did not exit cleanly, exit_code=255, description="exited with code 255". Please look in search.log for this peer in the Job Inspector for more info.

This error is coming for all the indexers.

I have read couple of splunk annwers and then removed huge csv's from lookups directory by blacklisting them from distsearch.conf, but still my searches are failing.

I am not able to do this :
index=summary

It throws error.
I checked the size of the bundles on search heads and indexers and the size of the bundle is same.
Then why am I getting error while searching.

Thanks ,
Usha

Tags (1)
0 Karma

jkat54
SplunkTrust
SplunkTrust

Open the job inspector and look in search.log for errors and post any you find there.

255 is an exit code from a python function (probably os.subprocess) and is probably related to file permissions on the disk.

Is the splunkd process running as the correct user? Did it run as root once and now it's running as less priveleged user now?

You may need to recursively chown the Splunk directory 'chown -Rf splunkuser:splunkgroup /path/to/splunk' after stopping Splunkd and insuring it will start as the correct user next time.

This is linux right?

0 Karma

usha_nittala
New Member

Splunk version is 6.1.4

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...