I'm getting the following errors in my splunkd.log file a lot;
02-19-2014 10:10:58.232 -0800 WARN FileClassifierManager - The file '/opt/splunk/var/spool/splunk/RMD596d1d44d452086c5_441184131.stash_new' is invalid. Reason: binary
02-19-2014 10:10:58.232 -0800 INFO TailingProcessor - Ignoring file '/opt/splunk/var/spool/splunk/RMD596d1d44d452086c5_441184131.stash_new' due to: binary
From what I've read, this is a known bug, SPL-59578.
The "good" workaround is to reschedule the summary indexing and run a backfill to regenerate the corrupted files. But my question is, how do I get from "RMD596d1d44d452086c5" to a search name?
Try this search:
| rest /services/search/jobs | where LIKE(id,"%RMD596d1d44d452086c5%") | table label
Try this search:
| rest /services/search/jobs | where LIKE(id,"%RMD596d1d44d452086c5%") | table label
Somesoni2,
That did it. Thanks.