After upgrade from 8.2.4 to 9.0.4.1 forwarders connect to indexers then after the Indexer cluster gets stabilized. All looked good - new data are delivered and indexed and searching works fine. How...
See more...
After upgrade from 8.2.4 to 9.0.4.1 forwarders connect to indexers then after the Indexer cluster gets stabilized. All looked good - new data are delivered and indexed and searching works fine. However, we start seeing the log messages below, WARN level messages, being populated into splunkd.log.: 05-31-2023 06:47:21.407 -0500 WARN SystemInfo [15415 TcpChannelThread] - Invalid file path /proc/1/cgroup while checking container status During the upgrade, no new apps were added and no container is used for splunk. This kind of messages are found 3-4 times/min by different components and also in pretty much all splunk entities, including SH, deployer, LM, indexers and CM. We would like an analysis for that one.