Splunk Search

transaction: keeporphans error after 4.3 upgrade?

twinspop
Influencer

This search works without issue in 4.2.4:

sourcetype="teledebug" | transaction keeporphans=1 host source startswith=ANI endswith=onhook

In 4.3 it appears to work, but it returns an error in red atop the results:

[splunk1] Streamed search execute failed because: Error in 'transam' command: Invalid argument: 'keeporphans=1'

Anyone else? Known bug?

EDIT: the error is coming from one of my 4.2.3 indexers. Weird. Any ideas? I'll upgrade asap and report back if it fixes the problem.

Tags (1)
0 Karma
1 Solution

Drainy
Champion

http://docs.splunk.com/Documentation/Splunk/4.2.3/SearchReference/Transaction

Keeporphans was introduced in version 4.2.4 so 4.2.3 indexers trying to run that search will fallover I am afraid, I think it is keepevicted or something similar.

View solution in original post

Drainy
Champion

http://docs.splunk.com/Documentation/Splunk/4.2.3/SearchReference/Transaction

Keeporphans was introduced in version 4.2.4 so 4.2.3 indexers trying to run that search will fallover I am afraid, I think it is keepevicted or something similar.

twinspop
Influencer

Multiple failures here. I didn't even realize I had a 4.2.3 indexer still. And then failed to read the error message correctly. Doh! Thanks.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...