Splunk Search

What would cause the dm_backfill_factory.py to run?

MasterOogway
Communicator

I have been seeing terrible search time results of late and found Splunk to be running
SplunkDeploymentMonitor/bin/scripted_inputs/dm_backfill_factory.py

Continuously which in turn chews up resources. When comparing this installation against a "like" install the other install does not run this Python script. What is the reason this might be running? I am looking for a good reason to turn it off without interrupting anything else within Splunk.

So far I have come up empty on what is causing it to run.

Thoughts?

Tags (1)
0 Karma
1 Solution

dart
Splunk Employee
Splunk Employee

It's the script that backfills the Deployment Monitor Index.

If you're deployment monitor is already populated, you can disable it.

AFAIK the only way to launch it is to hit the button in the Deployment Monitor app.

View solution in original post

MasterOogway
Communicator

Found it in the inputs.conf

[script:///emat/splunk/etc/apps/SplunkDeploymentMonitor/bin/scripted_inputs/dm_backfill_factory.py]
disabled = false
interval = 15
passAuth = admin

Turning to disabled = true

MasterOogway
Communicator

I am trying to find a way to disable the script but haven't found a way yet.

I disabled the dm_backfill.conf - disabled=1 but that failed.

33d22d46-a353-4972-9682-3cf55625e013]
dedup = 0
earliest = 1340776800.0
latest = 1341986400.0
maxjobs = 1
namespace = SplunkDeploymentMonitor
reverse = 1
saved_search = All indexers - regenerator
seed = 1342017493.05
status = 2
totaljobs = None
disabled = 1

....followed by a restart of Splunk, but it is still running. I want to have the Deployment Monitor running, just not this script, so I need to leave this enabled in the app.conf. Nothing to turn it off in the UI.

Any other thoughts on turning this script off short of uninstalling and reinstalling?

0 Karma

dart
Splunk Employee
Splunk Employee

It's the script that backfills the Deployment Monitor Index.

If you're deployment monitor is already populated, you can disable it.

AFAIK the only way to launch it is to hit the button in the Deployment Monitor app.

MasterOogway
Communicator

I disabled the script in the ../local/inputs.conf file.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...