Splunk Search

Index _internal doesn't return results when query from custom app

aaronhernandez
Explorer

Hi friends!

 

Im doing a search like

index=_internal

From a custom app, even if Im the admin user. I have a cluster Splunk architecture and still I obtain messages like this

Search results might be incomplete: the search process on the peer:XXXXX ended prematurely. Check the peer log, such as $SPLUNK_HOME/var/log/splunk/splunkd.log and as well as the search.log for the particular search.

Search process did not exit cleanly, exit_code=255, description="exited with code 255". Please look in search.log for this peer in the Job Inspector for more info.

 

But I can do the query from search app whitout any problem.

Is there a way to enable the _internal index for other apps?

Labels (1)
Tags (2)

tscroggins
Influencer

Hi @aaronhernandez,

Did you review the contents of the peer's search log? What were the last errors logged before the process terminated?

0 Karma

aaronhernandez
Explorer

Hi!

I've looking deeper on logs and found the next search.log from indexer

 

cat /opt/splunk/var/run/splunk/dispatch/remote_2204-ServerX_ta_1611562489.65879_17A6E718-C362-47B5-BB30-81E337E0515C/search.log
01-25-2021 02:14:49.428 INFO  dispatchRunner - Search process mode: preforked (reused process by new user) (build 08187535c166).
01-25-2021 02:14:49.428 INFO  dispatchRunner - registering build time modules, count=1
01-25-2021 02:14:49.428 INFO  dispatchRunner - registering search time components of build time module name=vix
01-25-2021 02:14:49.432 INFO  BundlesSetup - Setup stats for /opt/splunk/var/run/searchpeers/559ABE76-4C71-496F-ACED-02AD243E8BCE-1600840927: wallclock_elapsed_msec=58, cpu_time_used=0.046752, shared_services_generation=2, shared_services_population=1
01-25-2021 02:14:49.469 INFO  UserManagerPro - Load authentication: forcing roles="admin, alert_manager, alert_manager_user, power, user"
01-25-2021 02:14:49.470 INFO  UserManager - Setting user context: splunk-system-user
01-25-2021 02:14:49.470 INFO  UserManager - Done setting user context: NULL -> splunk-system-user
01-25-2021 02:14:49.471 INFO  UserManager - Unwound user context: splunk-system-user -> NULL
01-25-2021 02:14:49.471 INFO  UserManager - Setting user context: usuarioA
01-25-2021 02:14:49.471 INFO  UserManager - Done setting user context: NULL -> usuarioA
01-25-2021 02:14:49.472 INFO  UserManager - Unwound user context: usuarioA -> NULL
01-25-2021 02:14:49.472 INFO  LookupDataProvider - Clearing out lookup shared provider map
01-25-2021 02:14:49.472 ERROR dispatchRunner - RunDispatch::runDispatchThread threw error: Application does not exist: monitoring

 

The app monitoring exist!. The app was deployer from Deployer Server.

Tags (1)
0 Karma

aaronhernandez
Explorer

Hi!

 

Yes, and here is an example of this case

 

cat ./remote_2204-serverX_1611307647.11550_FCF715C2-4FCE-481F-9CDE-7DC5BCBDFCF9/search.log
01-22-2021 03:27:27.863 INFO  dispatchRunner - Search process mode: preforked (reused process) (build 08187535c166).
01-22-2021 03:27:27.863 INFO  dispatchRunner - registering build time modules, count=1
01-22-2021 03:27:27.863 INFO  dispatchRunner - registering search time components of build time module name=vix
01-22-2021 03:27:27.864 INFO  BundlesSetup - Setup stats for /opt/splunk/var/run/searchpeers/559ABE76-4C71-496F-ACED-02AD243E8BCE-1600840927: wallclock_elapsed_msec=83, cpu_time_used=0.0796310, shared_services_generation=2, shared_services_population=1
01-22-2021 03:27:27.865 INFO  UserManager - Setting user context: splunk-system-user
01-22-2021 03:27:27.865 INFO  UserManager - Done setting user context: NULL -> splunk-system-user
01-22-2021 03:27:27.865 INFO  UserManager - Unwound user context: splunk-system-user -> NULL
01-22-2021 03:27:27.865 INFO  UserManager - Setting user context: usuarioA
01-22-2021 03:27:27.865 INFO  UserManager - Done setting user context: NULL -> usuarioA
01-22-2021 03:27:27.866 INFO  dispatchRunner - search context: user="usuarioA", app="search", bs-pathname="/opt/splunk/var/run/searchpeers/559ABE76-4C71-496F-ACED-02AD243E8BCE-1600840927"
01-22-2021 03:27:27.866 INFO  SearchParser - PARSING: litsearch (index=_internal batman) | fields  keepcolorder=t "*" "_bkt" "_cd" "_si" "host" "index" "linecount" "source" "sourcetype" "splunk_server"  | remotetl  nb=300 et=1611304020.000000 lt=1611307647.000000 remove=true max_count=1000 max_prefetch=100
01-22-2021 03:27:27.866 INFO  SearchParser - PARSING: litsearch (index=_internal batman) | fields  keepcolorder=t "*" "_bkt" "_cd" "_si" "host" "index" "linecount" "source" "sourcetype" "splunk_server"  | remotetl  nb=300 et=1611304020.000000 lt=1611307647.000000 remove=true max_count=1000 max_prefetch=100
01-22-2021 03:27:27.866 INFO  UserManager - Setting user context: splunk-system-user
01-22-2021 03:27:27.866 INFO  UserManager - Done setting user context: usuarioA -> splunk-system-user
01-22-2021 03:27:27.866 INFO  UserManager - Setting user context: usuarioA
01-22-2021 03:27:27.866 INFO  UserManager - Done setting user context: splunk-system-user -> usuarioA
01-22-2021 03:27:27.867 INFO  UserManager - Unwound user context: usuarioA -> splunk-system-user
01-22-2021 03:27:27.867 INFO  UserManager - Unwound user context: splunk-system-user -> usuarioA
01-22-2021 03:27:27.867 INFO  DispatchCommandProcessor - Search requires the following indexes="[_internal]"
01-22-2021 03:27:27.867 INFO  IndexReaderIf - Loading Clustering bucket manifest file=/opt/splunk/var/run/splunk/cluster/search-buckets/search_sitedefault_gen77249.csv.gz
01-22-2021 03:27:27.867 INFO  DatabaseDirectoryManager - initDDMsFromSearchBucketManifest path=/opt/splunk/var/run/splunk/cluster/search-buckets/search_sitedefault_gen77249.csv.gz, indexWhiteList_size=1
01-22-2021 03:27:27.961 INFO  dispatchRunner - SearchPeerInitSearchMs=96
01-22-2021 03:27:27.961 INFO  dispatchRunner - Serial search pipeline for streaming search being launched.
01-22-2021 03:27:27.961 INFO  SearchPipelineExecutor - Number of StreamSearch pipelines launched=1
01-22-2021 03:27:27.961 INFO  SearchPipelineExecutor - Starting to transmit serialized search results.
01-22-2021 03:27:27.961 INFO  SearchPipelineExecutor - StreamSearch pipeline=0 is started in its own thread
01-22-2021 03:27:27.961 INFO  UserManager - Setting user context: usuarioA
01-22-2021 03:27:27.961 INFO  SearchPipelineExecutor - NormSerializeExecutorThread pipeline=0 is started in its own thread.
01-22-2021 03:27:27.961 INFO  UserManager - Done setting user context: NULL -> usuarioA
01-22-2021 03:27:27.961 INFO  SearchParser - PARSING: litsearch (index=_internal batman) | fields  keepcolorder=t "*" "_bkt" "_cd" "_si" "host" "index" "linecount" "source" "sourcetype" "splunk_server"  | remotetl  nb=300 et=1611304020.000000 lt=1611307647.000000 remove=true max_count=1000 max_prefetch=100
01-22-2021 03:27:28.005 INFO  CsvDataProvider - Reading schema for lookup table='xmlsecurity_eventcode_action_lookup', file size=57814, modtime=1600840980
01-22-2021 03:27:28.006 INFO  CsvDataProvider - Reading schema for lookup table='msdhcp_signature_lookup', file size=2274, modtime=1600840981
01-22-2021 03:27:28.006 INFO  CsvDataProvider - Reading schema for lookup table='windows_vendor_info_lookup', file size=189, modtime=1600840980
01-22-2021 03:27:28.006 INFO  CsvDataProvider - Reading schema for lookup table='windows_timesync_action_lookup', file size=43, modtime=1600840981
01-22-2021 03:27:28.006 INFO  CsvDataProvider - Reading schema for lookup table='windows_update_status_lookup', file size=342, modtime=1600840980
01-22-2021 03:27:28.006 INFO  CsvDataProvider - Reading schema for lookup table='wmi_user_account_status_lookup', file size=38, modtime=1600840980
01-22-2021 03:27:28.006 INFO  CsvDataProvider - Reading schema for lookup table='wmi_version_range_lookup', file size=37, modtime=1600840980
01-22-2021 03:27:28.007 INFO  CsvDataProvider - Reading schema for lookup table='windows_app_lookup', file size=575, modtime=1600840980
01-22-2021 03:27:28.007 INFO  CsvDataProvider - Reading schema for lookup table='endpoint_change_vendor_action_lookup', file size=186, modtime=1600840980
01-22-2021 03:27:28.007 INFO  CsvDataProvider - Reading schema for lookup table='endpoint_change_object_category_lookup', file size=89, modtime=1600840980
01-22-2021 03:27:28.007 INFO  CsvDataProvider - Reading schema for lookup table='endpoint_change_status_lookup', file size=54, modtime=1600840980
01-22-2021 03:27:28.007 INFO  CsvDataProvider - Reading schema for lookup table='endpoint_change_user_type_lookup', file size=40, modtime=1600840980
01-22-2021 03:27:28.008 INFO  CsvDataProvider - Reading schema for lookup table='splunk_object_category_lookup', file size=57, modtime=1600840981
01-22-2021 03:27:28.008 INFO  CsvDataProvider - Reading schema for lookup table='splunk_src_lookup', file size=26, modtime=1600840981
01-22-2021 03:27:28.008 INFO  CsvDataProvider - Reading schema for lookup table='cisco_action_lookup', file size=1065, modtime=1600840980
01-22-2021 03:27:28.008 INFO  CsvDataProvider - Reading schema for lookup table='cisco_asa_syslog_severity_lookup', file size=319, modtime=1600840980
01-22-2021 03:27:28.008 INFO  CsvDataProvider - Reading schema for lookup table='cisco_asa_change_analysis_lookup', file size=765, modtime=1600840980
01-22-2021 03:27:28.008 INFO  CsvDataProvider - Reading schema for lookup table='cisco_asa_ids_lookup', file size=55, modtime=1600840980
01-22-2021 03:27:28.008 INFO  CsvDataProvider - Reading schema for lookup table='cisco_asa_intrusion_severity_lookup', file size=1516, modtime=1600840980
01-22-2021 03:27:28.008 INFO  CsvDataProvider - Reading schema for lookup table='cisco_asa_intrusion_vendor_severity_lookup', file size=83, modtime=1600840980
01-22-2021 03:27:28.008 INFO  CsvDataProvider - Reading schema for lookup table='cisco_asa_vendor_class_lookup', file size=3421, modtime=1600840980
01-22-2021 03:27:28.008 INFO  CsvDataProvider - Reading schema for lookup table='ftnt_event_action_lookup', file size=850, modtime=1600840980
01-22-2021 03:27:28.008 INFO  CsvDataProvider - Reading schema for lookup table='ftnt_action_lookup', file size=360, modtime=1600840980
01-22-2021 03:27:28.009 INFO  CsvDataProvider - Reading schema for lookup table='ftnt_protocol_lookup', file size=1261, modtime=1600840980
01-22-2021 03:27:28.009 INFO  CsvDataProvider - Reading schema for lookup table='fs_notification_change_type_lookup', file size=70, modtime=1600840980
01-22-2021 03:27:28.009 INFO  CsvDataProvider - Reading schema for lookup table='windows_signature_lookup', file size=34650, modtime=1600840980
01-22-2021 03:27:28.009 INFO  CsvDataProvider - Reading schema for lookup table='windows_signature_lookup2', file size=1277, modtime=1600840980
01-22-2021 03:27:28.009 INFO  CsvDataProvider - Reading schema for lookup table='windows_event_descriptions', file size=35240, modtime=1600840980
01-22-2021 03:27:28.009 WARN  CsvDataProvider - Unable to read the size and modtime of the lookup file. lookup=sse_content_exported_lookup, path=
01-22-2021 03:27:28.009 ERROR CsvDataProvider - Could not read lookup table file ''.
01-22-2021 03:27:28.009 WARN  CsvDataProvider - Unable to read the size and modtime of the lookup file. lookup=sse_content_exported_lookup, path=
01-22-2021 03:27:28.009 ERROR CsvDataProvider - Could not read lookup table file ''.
01-22-2021 03:27:28.010 WARN  AutoLookupDriver - The lookup definition in transforms.conf/[LOOKUP-splunk_security_essentials] have "replicate=false" and is not available on remote peers.
01-22-2021 03:27:28.010 INFO  CsvDataProvider - Reading schema for lookup table='windows_audit_changes_lookup', file size=697, modtime=1600840980
01-22-2021 03:27:28.010 INFO  CsvDataProvider - Reading schema for lookup table='windows_action_lookup', file size=340, modtime=1600840980
01-22-2021 03:27:28.010 INFO  CsvDataProvider - Reading schema for lookup table='MSADGroupType', file size=109, modtime=1600840980
01-22-2021 03:27:28.010 INFO  CsvDataProvider - Reading schema for lookup table='windows_privilege_lookup', file size=1617, modtime=1600840980
01-22-2021 03:27:28.010 INFO  CsvDataProvider - Reading schema for lookup table='GroupType', file size=113, modtime=1600840980
01-22-2021 03:27:28.010 INFO  CsvDataProvider - Reading schema for lookup table='f5_ip_protocol_lookup', file size=1761, modtime=1600840980
01-22-2021 03:27:28.011 INFO  CsvDataProvider - Reading schema for lookup table='f5_snmp_trap_oid_lookup', file size=11656, modtime=1600840980
01-22-2021 03:27:28.012 INFO  SearchParser - PARSING: typer | tags
01-22-2021 03:27:28.092 INFO  FastTyper - found nodes count: comparisons=727, unique_comparisons=377, terms=20, unique_terms=16, phrases=46, unique_phrases=30, total leaves=793
01-22-2021 03:27:28.097 INFO  UserManager - Setting user context: usuarioA
01-22-2021 03:27:28.097 INFO  UserManager - Done setting user context: usuarioA -> usuarioA
01-22-2021 03:27:28.097 INFO  FastSearchFilter - Finished initializing IndexScopedFilter - trivial=0, nTerms=1, oTerms=0, host=0, source=0, sourcetype=0, linecount=0 exactCustomCmp=0
01-22-2021 03:27:28.097 INFO  UserManager - Unwound user context: usuarioA -> usuarioA
01-22-2021 03:27:28.097 INFO  IndexScopedSearch - ct=1611307647.000000 et=1611304020.000000 lt=1611307647.000000 dbsize=8
01-22-2021 03:27:28.098 INFO  UnifiedSearch - Initialization of search data structures took 87 ms
01-22-2021 03:27:28.098 INFO  UnifiedSearch - Processed search targeting arguments
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-CategoryString_for_windows
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-EventCodeDescription_for_windows
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-action_for_WinRegistry
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-action_for_fs_notification
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-action_for_win_timesync_status
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-action_for_windows0_security
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-action_for_windows1_security
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-action_for_windows2_security
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-action_for_windows_xmlsecurity
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-action_for_wmi_user_account_status
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-app0_for_windows_security
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-app1_for_windows_security
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-app2_for_windows_security
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-app3_for_windows_security
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-app4_for_windows_security
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-app_for_windows_system_ias
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-change_type_for_fs_notification
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-cisco-asa-action_lookup
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-cisco-asa_severity_expansion
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-cisco-pix-action_lookup
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-cisco_asa_change_analysis
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-cisco_asa_ids_lookup
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-cisco_asa_intrusion_severity_lookup
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-cisco_asa_severity_lookup
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-cisco_asa_vendor_class_lookup
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-cisco_fwsm_action_lookup
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-cisco_fwsm_intrusion_severity_lookup
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-cisco_fwsm_severity_lookup
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-cisco_pix_ids_lookup
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-cisco_pix_intrusion_severity_lookup
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-cisco_pix_severity_lookup
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-fgt_event_action
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-fgt_traffic_action
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-fgt_traffic_ftnt_protocol_lookup
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-fgt_utm_action
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-ip_proto
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-msadgroupclass
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-object_category_for_WinRegistry
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-object_category_for_fs_notification
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-object_category_for_splunk_access
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-object_status_for_fs_notification
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-oid
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-privilege_for_windows_security
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-range_for_wmi_version
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-signature_for_microsoft_dhcp
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-signature_for_windows
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-signature_for_windows3
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-src_for_splunk_access
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-status_for_WinRegistry
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-status_for_installedupdates
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-status_for_windows_system_update
01-22-2021 03:27:28.098 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-status_for_windowsupdatelog
01-22-2021 03:27:28.099 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-user_type_for_WinRegistry
01-22-2021 03:27:28.099 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-vendor_info_for_microsoft_dhcp
01-22-2021 03:27:28.099 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-vendor_info_for_windows_security
01-22-2021 03:27:28.099 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-vendor_info_for_windows_system
01-22-2021 03:27:28.099 INFO  AutoLookupDriver - Will use Lookup: LOOKUP-vendor_info_for_windowsupdatelog
01-22-2021 03:27:28.137 INFO  SearchOperator:kv - "splunk_internal_kv_mode" value found 0 times in bucket.
01-22-2021 03:27:28.138 WARN  SearchOperator:kv - buildRegexList provided empty conf key, ignoring.
01-22-2021 03:27:28.138 INFO  SearchOperator:kv - "splunk_internal_kv_mode" value found 0 times in bucket.
01-22-2021 03:27:28.138 INFO  Timeliner - Emitted 4 full events to info._remotetl_events
01-22-2021 03:27:28.138 INFO  SearchPipelineExecutor - Finished streaming: results.count=0
01-22-2021 03:27:28.138 WARN  SRSSerializer - writing 0 cols! field list=0
01-22-2021 03:27:28.138 INFO  UserManager - Unwound user context: usuarioA -> NULL
01-22-2021 03:27:28.138 INFO  SearchPipelineExecutor - StreamSearch pipleine=0 is finished.
01-22-2021 03:27:28.139 WARN  SRSSerializer - writing 0 cols! field list=0
01-22-2021 03:27:28.139 WARN  SRSSerializer - writing 0 cols! field list=0
01-22-2021 03:27:28.140 INFO  SearchPipelineExecutor - NormSerializeExecutorThread pipeline=0 is finished.
01-22-2021 03:27:28.140 INFO  SearchPipelineExecutor - Done transmitting serialized search results, total bytes transmitted 22899.
01-22-2021 03:27:28.140 INFO  dispatchRunner - Done with streaming search.
01-22-2021 03:27:28.144 INFO  ISearchOperator - 0x7f75e310a000 PREAD_HISTOGRAM: usec_1_8=931 usec_8_64=5 usec_64_512=26 usec_512_4096=0 usec_4096_32768=0 usec_32768_262144=0 usec_262144_INF=0
01-22-2021 03:27:28.145 INFO  SearchPipelineExecutor - Streamed Search Index Orchestrator has been shutdown.
01-22-2021 03:27:28.145 INFO  UserManager - Unwound user context: usuarioA -> NULL
01-22-2021 03:27:28.145 INFO  LookupDataProvider - Clearing out lookup shared provider map

 

All looks fine!. Still the same results. 

 

Tags (2)
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...