Splunk Search

Why is virtual index search showing no results found after installing Hunk?

rameez
Engager

Hello guys,

I installed hunk and followed its tutorial. I have checked the HDFS location and it seems fine. Hadoop version looks fine as well. The search.log is in pastebin http://pastebin.com/rrEJnLNA.

Any help would be appreciated

Tags (4)
0 Karma
1 Solution

Ledion_Bitincka
Splunk Employee
Splunk Employee

it seems like "Hadoop Home" is not pointing to a valid dir - not the missing leading / in the path: "/bin/bash: usr/lib/hado ..."

10-13-2014 06:56:45.686 ERROR ERP.PonyProvider -  /bin/bash: usr/lib/hadoop/bin/hadoop: No such file or directory
10-13-2014 06:56:45.687 ERROR SearchOperator:stdin - Cannot consume data with unset stream_type
10-13-2014 06:56:45.687 ERROR ExternalResultProvider - Error in 'SearchOperator:stdin': Cannot consume data with unset stream_type

View solution in original post

Ledion_Bitincka
Splunk Employee
Splunk Employee

it seems like "Hadoop Home" is not pointing to a valid dir - not the missing leading / in the path: "/bin/bash: usr/lib/hado ..."

10-13-2014 06:56:45.686 ERROR ERP.PonyProvider -  /bin/bash: usr/lib/hadoop/bin/hadoop: No such file or directory
10-13-2014 06:56:45.687 ERROR SearchOperator:stdin - Cannot consume data with unset stream_type
10-13-2014 06:56:45.687 ERROR ExternalResultProvider - Error in 'SearchOperator:stdin': Cannot consume data with unset stream_type
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...