Splunk Search

What is this error in dispatch process?

kkovanis
New Member
0400 ERROR DispatchProcess - String not found in literals.conf: DISPATCHCOMM:FAILED_TO_START_PROCESS

I need help finding out what this is and how to fix it.
Why is the dispatch process not working? What is dispatchcomm?
What do you use instead of literals.conf?

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@kkovanis - Just make sure you have not made any changes to Splunk's internal configuration file or added any local literals.conf file.

0 Karma

codebuilder
Influencer

Did you recently upgrade? literals.conf is deprecated. You should use messages.conf instead.

If you did not upgrade, make sure that literals.conf is owned by splunk:splunk and has appropriate read/write access ,and also that literals.conf contains valid stanzas and string definitions.

The dispatch process is what returns search results from your indexers to your search head(s).

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...