Monitoring Splunk

SOLVED - Error Banner Message exit_code=255 btool command

bleung93
Path Finder

Search process did not exit cleanly, exit_code=255, description="exited with code 255". Please look in search.log for this peer in the Job Inspector for more info.

Getting this error when executing the search " | btool indexes". While executing this search in the SOS app, the sos_server field is populated with the search head and indexers. When executing through the search app, banner appears and the sos_server field only shows the search head.

This is probably a configuration error, but splunkd.log is not showing anything with WARN or ERROR.

sos app is set to global, btool is set to global

Tags (4)
1 Solution

bleung93
Path Finder

Hello, this has been solved. Turns out that we were not syncing properly to all of the indexers, which gave the error. The btool command was not installed on the indexers themselves because he lack of sync.

View solution in original post

0 Karma

edwardWorldline
Engager

How do you sync all the indexers in the cluster?

0 Karma

bleung93
Path Finder

Hello, this has been solved. Turns out that we were not syncing properly to all of the indexers, which gave the error. The btool command was not installed on the indexers themselves because he lack of sync.

0 Karma

edwardWorldline
Engager

How do you sync all the indexers in a cluster? Is there another thread that explains how this was solved?

0 Karma

hexx
Splunk Employee
Splunk Employee

This really looks as if the updated permissions for the btool.py custom search command are not being propagated to your peers, which therefore cannot execute it outside of the S.o.S app.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

What does the search.log file for that job say?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Splunk is officially part of Cisco

Revolutionizing how our customers build resilience across their entire digital footprint.   Splunk ...

Splunk APM & RUM | Planned Maintenance March 26 - March 28, 2024

There will be planned maintenance for Splunk APM and RUM between March 26, 2024 and March 28, 2024 as ...