Splunk Search

Index _internal doesn't return results when query from custom app

aaronhernandez
Explorer

Hi friends!

 

Im doing a search like

index=_internal

From a custom app, even if Im the admin user. I have a cluster Splunk architecture and still I obtain messages like this

Search results might be incomplete: the search process on the peer:XXXXX ended prematurely. Check the peer log, such as $SPLUNK_HOME/var/log/splunk/splunkd.log and as well as the search.log for the particular search.

Search process did not exit cleanly, exit_code=255, description="exited with code 255". Please look in search.log for this peer in the Job Inspector for more info.

 

But I can do the query from search app whitout any problem.

Is there a way to enable the _internal index for other apps?

Labels (1)
Tags (2)

tscroggins
Influencer

Hi @aaronhernandez,

Did you review the contents of the peer's search log? What were the last errors logged before the process terminated?

0 Karma

aaronhernandez
Explorer

Hi!

I've looking deeper on logs and found the next search.log from indexer

 

cat /opt/splunk/var/run/splunk/dispatch/remote_2204-ServerX_ta_1611562489.65879_17A6E718-C362-47B5-BB30-81E337E0515C/search.log
01-25-2021 02:14:49.428 INFO  dispatchRunner - Search process mode: preforked (reused process by new user) (build 08187535c166).
01-25-2021 02:14:49.428 INFO  dispatchRunner - registering build time modules, count=1
01-25-2021 02:14:49.428 INFO  dispatchRunner - registering search time components of build time module name=vix
01-25-2021 02:14:49.432 INFO  BundlesSetup - Setup stats for /opt/splunk/var/run/searchpeers/559ABE76-4C71-496F-ACED-02AD243E8BCE-1600840927: wallclock_elapsed_msec=58, cpu_time_used=0.046752, shared_services_generation=2, shared_services_population=1
01-25-2021 02:14:49.469 INFO  UserManagerPro - Load authentication: forcing roles="admin, alert_manager, alert_manager_user, power, user"
01-25-2021 02:14:49.470 INFO  UserManager - Setting user context: splunk-system-user
01-25-2021 02:14:49.470 INFO  UserManager - Done setting user context: NULL -> splunk-system-user
01-25-2021 02:14:49.471 INFO  UserManager - Unwound user context: splunk-system-user -> NULL
01-25-2021 02:14:49.471 INFO  UserManager - Setting user context: usuarioA
01-25-2021 02:14:49.471 INFO  UserManager - Done setting user context: NULL -> usuarioA
01-25-2021 02:14:49.472 INFO  UserManager - Unwound user context: usuarioA -> NULL
01-25-2021 02:14:49.472 INFO  LookupDataProvider - Clearing out lookup shared provider map
01-25-2021 02:14:49.472 ERROR dispatchRunner - RunDispatch::runDispatchThread threw error: Application does not exist: monitoring

 

The app monitoring exist!. The app was deployer from Deployer Server.

Tags (1)
0 Karma

aaronhernandez
Explorer

Hi!

 

Yes, and here is an example of this case

 

cat ./remote_2204-serverX_1611307647.11550_FCF715C2-4FCE-481F-9CDE-7DC5BCBDFCF9/search.log
01-22-2021 03:27:27.863 INFO  dispatchRunner - Search process mode: preforked (reused process) (build 08187535c166).
01-22-2021 03:27:27.863 INFO  dispatchRunner - registering build time modules, count=1
01-22-2021 03:27:27.863 INFO  dispatchRunner - registering search time components of build time module name=vix
01-22-2021 03:27:27.864 INFO  BundlesSetup - Setup stats for /opt/splunk/var/run/searchpeers/559ABE76-4C71-496F-ACED-02AD243E8BCE-1600840927: wallclock_elapsed_msec=83, cpu_time_used=0.0796310, shared_services_generation=2, shared_services_population=1
01-22-2021 03:27:27.865 INFO  UserManager - Setting user context: splunk-system-user
01-22-2021 03:27:27.865 INFO  UserManager - Done setting user context: NULL -> splunk-system-user
01-22-2021 03:27:27.865 INFO  UserManager - Unwound user context: splunk-system-user -> NULL
01-22-2021 03:27:27.865 INFO  UserManager - Setting user context: usuarioA
01-22-2021 03:27:27.865 INFO  UserManager - Done setting user context: NULL -> usuarioA
01-22-2021 03:27:27.866 INFO  dispatchRunner - search context: user="usuarioA", app="search", bs-pathname="/opt/splunk/var/run/searchpeers/559ABE76-4C71-496F-ACED-02AD243E8BCE-1600840927"
01-22-2021 03:27:27.866 INFO  SearchParser - PARSING: litsearch (index=_internal batman) | fields  keepcolorder=t "*" "_bkt" "_cd" "_si" "host" "index" "linecount" "source" "sourcetype" "splunk_server"  | remotetl  nb=300 et=1611304020.000000 lt=1611307647.000000 remove=true max_count=1000 max_prefetch=100
01-22-2021 03:27:27.866 INFO  SearchParser - PARSING: litsearch (index=_internal batman) | fields  keepcolorder=t "*" "_bkt" "_cd" "_si" "host" "index" "linecount" "source" "sourcetype" "splunk_server"  | remotetl  nb=300 et=1611304020.000000 lt=1611307647.000000 remove=true max_count=1000 max_prefetch=100
01-22-2021 03:27:27.866 INFO  UserManager - Setting user context: splunk-system-user
01-22-2021 03:27:27.866 INFO  UserManager - Done setting user context: usuarioA -> splunk-system-user
01-22-2021 03:27:27.866 INFO  UserManager - Setting user context: usuarioA
01-22-2021 03:27:27.866 INFO  UserManager - Done setting user context: splunk-system-user -> usuarioA
01-22-2021 03:27:27.867 INFO  UserManager - Unwound user context: usuarioA -> splunk-system-user
01-22-2021 03:27:27.867 INFO  UserManager - Unwound user context: splunk-system-user -> usuarioA
01-22-2021 03:27:27.867 INFO  DispatchCommandProcessor - Search requires the following indexes="[_internal]"
01-22-2021 03:27:27.867 INFO  IndexReaderIf - Loading Clustering bucket manifest file=/opt/splunk/var/run/splunk/cluster/search-buckets/search_sitedefault_gen77249.csv.gz
01-22-2021 03:27:27.867 INFO  DatabaseDirectoryManager - initDDMsFromSearchBucketManifest path=/opt/splunk/var/run/splunk/cluster/search-buckets/search_sitedefault_gen77249.csv.gz, indexWhiteList_size=1
01-22-2021 03:27:27.961 INFO  dispatchRunner - SearchPeerInitSearchMs=96
01-22-2021 03:27:27.961 INFO  dispatchRunner - Serial search pipeline for streaming search being launched.
01-22-2021 03:27:27.961 INFO  SearchPipelineExecutor - Number of StreamSearch pipelines launched=1
01-22-2021 03:27:27.961 INFO  SearchPipelineExecutor - Starting to transmit serialized search results.
01-22-2021 03:27:27.961 INFO  SearchPipelineExecutor - StreamSearch pipeline=0 is started in its own thread
01-22-2021 03:27:27.961 INFO  UserManager - Setting user context: usuarioA
01-22-2021 03:27:27.961 INFO  SearchPipelineExecutor - NormSerializeExecutorThread pipeline=0 is started in its own thread.
01-22-2021 03:27:27.961 INFO  UserManager - Done setting user context: NULL -> usuarioA
01-22-2021 03:27:27.961 INFO  SearchParser - PARSING: litsearch (index=_internal batman) | fields  keepcolorder=t "*" "_bkt" "_cd" "_si" "host" "index" "linecount" "source" "sourcetype" "splunk_server"  | remotetl  nb=300 et=1611304020.000000 lt=1611307647.000000 remove=true max_count=1000 max_prefetch=100
01-22-2021 03:27:28.005 INFO  CsvDataProvider - Reading schema for lookup table='xmlsecurity_eventcode_action_lookup', file size=57814, modtime=1600840980
01-22-2021 03:27:28.006 INFO  CsvDataProvider - Reading schema for lookup table='msdhcp_signature_lookup', file size=2274, modtime=1600840981
01-22-2021 03:27:28.006 INFO  CsvDataProvider - Reading schema for lookup table='windows_vendor_info_lookup', file size=189, modtime=1600840980
01-22-2021 03:27:28.006 INFO  CsvDataProvider - Reading schema for lookup table='windows_timesync_action_lookup', file size=43, modtime=1600840981
01-22-2021 03:27:28.006 INFO  CsvDataProvider - Reading schema for lookup table='windows_update_status_lookup', file size=342, modtime=1600840980
01-22-2021 03:27:28.006 INFO  CsvDataProvider - Reading schema for lookup table='wmi_user_account_status_lookup', file size=38, modtime=1600840980
01-22-2021 03:27:28.006 INFO  CsvDataProvider - Reading schema for lookup table='wmi_version_range_lookup', file size=37, modtime=1600840980
01-22-2021 03:27:28.007 INFO  CsvDataProvider - Reading schema for lookup table='windows_app_lookup', file size=575, modtime=1600840980
01-22-2021 03:27:28.007 INFO  CsvDataProvider - Reading schema for lookup table='endpoint_change_vendor_action_lookup', file size=186, modtime=1600840980
01-22-2021 03:27:28.007 INFO  CsvDataProvider - Reading schema for lookup table='endpoint_change_object_category_lookup', file size=89, modtime=1600840980
01-22-2021 03:27:28.007 INFO  CsvDataProvider - Reading schema for lookup table='endpoint_change_status_lookup', file size=54, modtime=1600840980
01-22-2021 03:27:28.007 INFO  CsvDataProvider - Reading schema for lookup table='endpoint_change_user_type_lookup', file size=40, modtime=1600840980
01-22-2021 03:27:28.008 INFO  CsvDataProvider - Reading schema for lookup table='splunk_object_category_lookup', file size=57, modtime=1600840981
01-22-2021 03:27:28.008 INFO  CsvDataProvider - Reading schema for lookup table='splunk_src_lookup', file size=26, modtime=1600840981
01-22-2021 03:27:28.008 INFO  CsvDataProvider - Reading schema for lookup table='cisco_action_lookup', file size=1065, modtime=1600840980
01-22-2021 03:27:28.008 INFO  CsvDataProvider - Reading schema for lookup table='cisco_asa_syslog_severity_lookup', file size=319, modtime=1600840980
01-22-2021 03:27:28.008 INFO  CsvDataProvider - Reading schema for lookup table='cisco_asa_change_analysis_lookup', file size=765, modtime=1600840980
01-22-2021 03:27:28.008 INFO  CsvDataProvider - Reading schema for lookup table='cisco_asa_ids_lookup', file size=55, modtime=1600840980
01-22-2021 03:27:28.008 INFO  CsvDataProvider - Reading schema for lookup table='cisco_asa_intrusion_severity_lookup', file size=1516, modtime=1600840980
01-22-2021 03:27:28.008 INFO  CsvDataProvider - Reading schema for lookup table='cisco_asa_intrusion_vendor_severity_lookup', file size=83, modtime=1600840980
01-22-2021 03:27:28.008 INFO  CsvDataProvider - Reading schema for lookup table='cisco_asa_vendor_class_lookup', file size=3421, modtime=1600840980
01-22-2021 03:27:28.008 INFO  CsvDataProvider - Reading schema for lookup table='ftnt_event_action_lookup', file size=850, modtime=1600840980
01-22-2021 03:27:28.008 INFO  CsvDataProvider - Reading schema for lookup table='ftnt_action_lookup', file size=360, modtime=1600840980
01-22-2021 03:27:28.009 INFO  CsvDataProvider - Reading schema for lookup table='ftnt_protocol_lookup', file size=1261, modtime=1600840980
01-22-2021 03:27:28.009 INFO  CsvDataProvider - Reading schema for lookup table='fs_notification_change_type_lookup', file size=70, modtime=1600840980
01-22-2021 03:27:28.009 INFO  CsvDataProvider - Reading schema for lookup table='windows_signature_lookup', file size=34650, modtime=1600840980
01-22-2021 03:27:28.009 INFO  CsvDataProvider - Reading schema for lookup table='windows_signature_lookup2', file size=1277, modtime=1600840980
01-22-2021 03:27:28.009 INFO  CsvDataProvider - Reading schema for lookup table='windows_event_descriptions', file size=35240, modtime=1600840980
01-22-2021 03:27:28.009 WARN  CsvDataProvider - Unable to read the size and modtime of the lookup file. lookup=sse_content_exported_lookup, path=
01-22-2021 03:27:28.009 ERROR CsvDataProvider - Could not read lookup table file ''.
01-22-2021 03:27:28.009 WARN  CsvDataProvider - Unable to read the size and modtime of the lookup file. lookup=sse_content_exported_lookup, path=
01-22-2021 03:27:28.009 ERROR CsvDataProvider - Could not read lookup table file ''.
01-22-2021 03:27:28.010 WARN  AutoLookupDriver - The lookup definition in transforms.conf/[LOOKUP-splunk_security_essentials] have "replicate=false" and is not available on remote peers.
01-22-2021 03:27:28.010 INFO  CsvDataProvider - Reading schema for lookup table='windows_audit_changes_lookup', file size=697, modtime=1600840980
01-22-2021 03:27:28.010 INFO  CsvDataProvider - Reading schema for lookup table='windows_action_lookup', file size=340, modtime=1600840980
01-22-2021 03:27:28.010 INFO  CsvDataProvider - Reading schema for lookup table='MSADGroupType', file size=109, modtime=1600840980
01-22-2021 03:27:28.010 INFO  CsvDataProvider - Reading schema for lookup table='windows_privilege_lookup', file size=1617, modtime=1600840980
01-22-2021 03:27:28.010 INFO  CsvDataProvider - Reading schema for lookup table='GroupType', file size=113, modtime=1600840980
01-22-2021 03:27:28.010 INFO  CsvDataProvider - Reading schema for lookup table='f5_ip_protocol_lookup', file size=1761, modtime=1600840980
01-22-2021 03:27:28.011 INFO  CsvDataProvider - Reading schema for lookup table='f5_snmp_trap_oid_lookup', file size=11656, modtime=1600840980
01-22-2021 03:27:28.012 INFO  SearchParser - PARSING: typer | tags
01-22-2021 03:27:28.092 INFO  FastTyper - found nodes count: comparisons=727, unique_comparisons=377, terms=20, unique_terms=16, phrases=46, unique_phrases=30, total leaves=793
01-22-2021 03:27:28.097 INFO  UserManager - Setting user context: usuarioA
01-22-2021 03:27:28.097 INFO  UserManager - Done setting user context: usuarioA -> usuarioA
01-22-2021 03:27:28.097 INFO  FastSearchFilter - Finished initializing IndexScopedFilter - trivial=0, nTerms=1, oTerms=0, host=0, source=0, sourcetype=0, linecount=0 exactCustomCmp=0
01-22-2021 03:27:28.097 INFO  UserManager - Unwound user context: usuarioA -> usuarioA
01-22-2021 03:27:28.097 INFO  IndexScopedSearch - ct=1611307647.000000 et=1611304020.000000 lt=1611307647.000000 dbsize=8
01-22-2021 03:27:28.098 INFO  UnifiedSearch - Initialization of search data structures took 87 ms
01-22-2021 03:27:28.098 INFO  UnifiedSearch - Processed search targeting arguments
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-CategoryString_for_windows
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-EventCodeDescription_for_windows
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-action_for_WinRegistry
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-action_for_fs_notification
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-action_for_win_timesync_status
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-action_for_windows0_security
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-action_for_windows1_security
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-action_for_windows2_security
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-action_for_windows_xmlsecurity
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-action_for_wmi_user_account_status
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-app0_for_windows_security
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-app1_for_windows_security
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-app2_for_windows_security
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-app3_for_windows_security
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-app4_for_windows_security
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-app_for_windows_system_ias
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-change_type_for_fs_notification
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-cisco-asa-action_lookup
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-cisco-asa_severity_expansion
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-cisco-pix-action_lookup
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-cisco_asa_change_analysis
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-cisco_asa_ids_lookup
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-cisco_asa_intrusion_severity_lookup
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-cisco_asa_severity_lookup
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-cisco_asa_vendor_class_lookup
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-cisco_fwsm_action_lookup
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-cisco_fwsm_intrusion_severity_lookup
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-cisco_fwsm_severity_lookup
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-cisco_pix_ids_lookup
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-cisco_pix_intrusion_severity_lookup
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-cisco_pix_severity_lookup
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-fgt_event_action
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-fgt_traffic_action
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-fgt_traffic_ftnt_protocol_lookup
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-fgt_utm_action
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-ip_proto
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-msadgroupclass
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-object_category_for_WinRegistry
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-object_category_for_fs_notification
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-object_category_for_splunk_access
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-object_status_for_fs_notification
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-oid
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-privilege_for_windows_security
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-range_for_wmi_version
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-signature_for_microsoft_dhcp
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-signature_for_windows
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-signature_for_windows3
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-src_for_splunk_access
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-status_for_WinRegistry
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-status_for_installedupdates
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-status_for_windows_system_update
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-status_for_windowsupdatelog
01-22-2021 03:27:28.099 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-user_type_for_WinRegistry
01-22-2021 03:27:28.099 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-vendor_info_for_microsoft_dhcp
01-22-2021 03:27:28.099 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-vendor_info_for_windows_security
01-22-2021 03:27:28.099 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-vendor_info_for_windows_system
01-22-2021 03:27:28.099 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-vendor_info_for_windowsupdatelog
01-22-2021 03:27:28.137 INFO  SearchOperator:kv - "splunk_internal_kv_mode" value found 0 times in bucket.
01-22-2021 03:27:28.138 WARN  SearchOperator:kv - buildRegexList provided empty conf key, ignoring.
01-22-2021 03:27:28.138 INFO  SearchOperator:kv - "splunk_internal_kv_mode" value found 0 times in bucket.
01-22-2021 03:27:28.138 INFO  Timeliner - Emitted 4 full events to info._remotetl_events
01-22-2021 03:27:28.138 INFO  SearchPipelineExecutor - Finished streaming: results.count=0
01-22-2021 03:27:28.138 WARN  SRSSerializer - writing 0 cols! field list=0
01-22-2021 03:27:28.138 INFO  UserManager - Unwound user context: usuarioA -> NULL
01-22-2021 03:27:28.138 INFO  SearchPipelineExecutor - StreamSearch pipleine=0 is finished.
01-22-2021 03:27:28.139 WARN  SRSSerializer - writing 0 cols! field list=0
01-22-2021 03:27:28.139 WARN  SRSSerializer - writing 0 cols! field list=0
01-22-2021 03:27:28.140 INFO  SearchPipelineExecutor - NormSerializeExecutorThread pipeline=0 is finished.
01-22-2021 03:27:28.140 INFO  SearchPipelineExecutor - Done transmitting serialized search results, total bytes transmitted 22899.
01-22-2021 03:27:28.140 INFO  dispatchRunner - Done with streaming search.
01-22-2021 03:27:28.144 INFO  ISearchOperator - 0x7f75e310a000 PREAD_HISTOGRAM: usec_1_8=931 usec_8_64=5 usec_64_512=26 usec_512_4096=0 usec_4096_32768=0 usec_32768_262144=0 usec_262144_INF=0
01-22-2021 03:27:28.145 INFO  SearchPipelineExecutor - Streamed Search Index Orchestrator has been shutdown.
01-22-2021 03:27:28.145 INFO  UserManager - Unwound user context: usuarioA -> NULL
01-22-2021 03:27:28.145 INFO  LookupDataProvider - Clearing out lookup shared provider map

 

All looks fine!. Still the same results. 

 

Tags (2)
0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...