Getting Data In

REST error in DMC Index Detail

cboillot
Contributor

In the DMC, I am seeing errors like below when looking at Index Detail.

[<SplunkServerName>] REST Processor: Failed to fetch REST endpoint uri=https://127.0.0.1:8089/services/data/indexes/<IndexName>?count=0 from server https://127.0.0.1:8089. Check that the URI path provided exists in the REST API.

and

[subsearch]: [<SplunkServerName>] REST Processor: Failed to fetch REST endpoint uri=https://127.0.0.1:8089/services/data/indexes-extended/<IndexName>?count=0 from server https://127.0.0.1:8089. Check that the URI path provided exists in the REST API

I don't see any reference to the /services/data in the REST endpoints. I am not sure what could be wrong.

Is this telling me that, on that Spunk Server, it is not seeing that index?

0 Karma

Paul1896
Path Finder

@cboillotDid you solved the issue in your DMC?

0 Karma

matthewpearce
Explorer

I received the same problem in the DMC after upgrading from 7.2.4 to Splunk 8.0.2.1. It appeared to be fixed after I adjusted the cluster master to forward logs to the indexers.

0 Karma

Vijeta
Influencer

Use this, instead of services use servicesNS

|rest /servicesNS/-/-/data/indexes/<IndexName>

0 Karma

cboillot
Contributor

Still getting the sames errors, now with NS added. With or without the /-/-/.

0 Karma

Vijeta
Influencer

@cboillot are you able to fetch any other end-points. Probably your id does not have permissions for rest calls.

0 Karma

cboillot
Contributor

Odd, i should have full Admin rights.

0 Karma

jbrinkman
Explorer

Do the hosts the error is thrown on actually have the index created? I see the same error for HFs configured with the server role of indexer in the monitoring console. So they are getting pinged by the search through rest even though they don't have the index created or any knowledge of it (not keeping the indexes updated on the HF since we don't do any searching there).

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...