Monitoring Splunk

SOLVED - Error Banner Message exit_code=255 btool command

bleung93
Path Finder

Search process did not exit cleanly, exit_code=255, description="exited with code 255". Please look in search.log for this peer in the Job Inspector for more info.

Getting this error when executing the search " | btool indexes". While executing this search in the SOS app, the sos_server field is populated with the search head and indexers. When executing through the search app, banner appears and the sos_server field only shows the search head.

This is probably a configuration error, but splunkd.log is not showing anything with WARN or ERROR.

sos app is set to global, btool is set to global

Tags (4)
1 Solution

bleung93
Path Finder

Hello, this has been solved. Turns out that we were not syncing properly to all of the indexers, which gave the error. The btool command was not installed on the indexers themselves because he lack of sync.

View solution in original post

0 Karma

edwardWorldline
Engager

How do you sync all the indexers in the cluster?

0 Karma

bleung93
Path Finder

Hello, this has been solved. Turns out that we were not syncing properly to all of the indexers, which gave the error. The btool command was not installed on the indexers themselves because he lack of sync.

0 Karma

edwardWorldline
Engager

How do you sync all the indexers in a cluster? Is there another thread that explains how this was solved?

0 Karma

hexx
Splunk Employee
Splunk Employee

This really looks as if the updated permissions for the btool.py custom search command are not being propagated to your peers, which therefore cannot execute it outside of the S.o.S app.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

What does the search.log file for that job say?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...