Deployment Architecture

Why are we are receiving error "-0500 ERROR DataModelEvaluator - Data model 'Security_DSB' was not found" search head instances?

Hemnaath
Motivator

Hi All,

We are getting this error in Splunk search head instances -0500 ERROR DataModelEvaluator - Data model 'Security_DSB' was not found.

We are getting the above error message in splunkd.log, not sure what as went wrong really and why we are getting this error message in splunkd.log after restarting the Splunk services. Kindly guide us in fixing this issue.

0500 ERROR DataModelEvaluator - Data model 'Security_DSB' was not found.
0500 ERROR DataModelEvaluator - Data model 'Security_DSB' was not found.
0500 ERROR DataModelEvaluator - Data model 'Security_DSB' was not found.
0500 ERROR DataModelEvaluator - Data model 'Security_DSB' was not found.

thanks in advance.

0 Karma

sves
Explorer

In the case of my customer, the data model json file was missing, and the datamodels.conf was set up with acceleration = 1. So every 5 minutes, Splunk would be complaining. Simply removing references to the missing data model is an easy fix. Or, recreate the data model from backup if one is available.

I see in other cases this has to do with permission - check out this answers article

0 Karma

Hemnaath
Motivator

Hi All, Can anyone throw me some lights on this error .

thanks in advance.

0 Karma

sves
Explorer

For now, all the light I can shed is that I see athe exact same error (different data model though) with one of my Splunk customers. The "-0500" in the beginning of your line is your time zone, so not really a part of the message. I will post my findings if I figure out what is going on with this error message.

0 Karma

sves
Explorer

Found this here on Answers

0 Karma

Hemnaath
Motivator

thanks sves for you are update.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...