Security

Why do we get the exited with code 255 error for each indexer?

danielbb
Motivator

When running | datamodel Intrusion_Detection search I get the following error message for each indexer -

[<indexer name>] Search process did not exit cleanly, exit_code=255, description="exited with code 255". Please look in search.log for this peer in the Job Inspector for more info. 

What can it be?

Tags (1)
0 Karma

MuS
SplunkTrust
SplunkTrust

Hi danielbb,

check the OS logs of your indexer, one of the reasons for this can be that your search job was killed by OOM (Out of Memory) Killer .. assuming you are running the indexers on nix.

cheers, MuS

danielbb
Motivator

@MuS, I've been working with Support on that and we found out that all the indexers throw the following error -

-- 10-16-2019 16:03:39.534 ERROR SearchParser - The search specifies a macro varonis_index that cannot be found. Reasons include: the macro name is misspelled, you do not have "read" permission for the macro, or the macro has not been shared with this application. Click Settings, Advanced search, Search Macros to view macro information.

We also saw that when running index=_internal, we see the same error (many times), but in the case of index=_internal, this error doesn't prevent the command from completing its work and display the results.

A similar thread at ERROR SearchParser - The search specifies a macro 'cs_get_index' that cannot be found.

0 Karma

danielbb
Motivator

Support is saying that every search I submit is checked against my eventtype.confs

0 Karma

danielbb
Motivator
0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...