Ok, so thanks to user "MuS" I was able to find the exit statuses under $SPLUNK_HOME/lib/python2.7/site-packages/splunk/clilib/cli.py and to confirm, these are the exit codes for the Splunk command line tool:
ERR_NOERR = 0
ERR_NUMARGS = 1
ERR_UNKNOWN = 2
ERR_AUTH = 3
ERR_ARG = 4
ERR_DOTSPLUNK = 5
ERR_VERSION = 6
ERR_PIPE = 7
ERR_STOP = 21
ERR_SPLUNKD_DOWN = 22
ERR_NO_ENDPOINT = 23
ERR_INVALID_STATUS_CODE = 24
ERR_AUTH_TOKEN_XML = 25
ERR_REST = 26
ERR_SPLUNKD = 27
ERR_SUCCESS = 28
Every night, around 1AM, I'm seeing exit codes for different indexers (usually a different one every night) that exits with 8 (which isn't defined!?), 7 (there aren't any pipes being sent!?), 6 (all versions are the same), and now 5 (DOTSPLUNK?). Can anyone point me in a direction that would explain why the Splunk CLI would output these exit codes through a command ( $SPLUNK_HOME/bin/splunk status ) that runs every 5 minutes, but only throws these errors around 1AM?
I'm running the latest version of Splunk Enterprise on an array of different hosts in an isolated lab.
Thank you!
... View more