Splunk Search

Why did request in search head fail to apply delete to some metadata?

gitingua
Communicator

Hello dear colleagues, has anyone encountered this error, I checked search.log for inconsistent metadata.

Help me decide.

Снимок экрана 2022-02-28 в 17.52.07.png

I have a request in SH, when I drive it I get this error

Labels (3)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please share the query that produced the errors.  Have you checked search.log?  What did it say?

---
If this reply helps you, Karma would be appreciated.
0 Karma

gitingua
Communicator

what is related to the error is this

WARN  DownloadRemoteDataTransaction - Got status code: 204 ( No Content) from https://ip:8089/services/search/jobs/remote_splunk-sh_md_admin__admin__sysadmin__search1_md_DEE0755C...

03-01-2022 11:02:36.723 WARN  DownloadRemoteDataTransaction - Failed to download search.log from remote peer 'splunk-idx', uri='https://ip:8089', sid='remote_splunk-sh_md_admin__admin__sysadmin__search1_md_DEE0755CDB96'

 

@richgalloway 

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...