Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Getting TailReader - File descriptor cache is full (100), trimming in one of the splunk heavyforwarder ? How to fix this issue.

$
0
0
Currently we have two heavy forwarder to configured to forward the data to the indexer. Just wanted to know what are the files being captured from both the servers using the below query. We are using **Splunk HF version 6.4.0** host =splunk01* sourcetype=splunkd index=_internal "*syslog*" but I am getting no result found , when checked in the splunkd.log I could see this errors 08-11-2016 07:06:58.118 -0400 INFO HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_x.x.x.x_8089_splunk01.xxxx.com_splunk01.xxx.com_7xxxx1-XXXXX-XXX-XXX-XXXX 08-11-2016 07:06:58.128 -0400 INFO HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_x.x.x.x_8089_splunk01.xxxx.com_splunk01.xxx.com_7xxxx1-XXXXX-XXX-XXX-XXXX 08-11-2016 07:06:58.156 -0400 INFO HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_x.x.x.x_8089_splunk01.xxxx.com_splunk01.xxx.com_7xxxx1-XXXXX-XXX-XXX-XXXX 08-11-2016 07:07:45.496 -0400 INFO TailReader - File descriptor cache is full (100), trimming... 08-11-2016 07:07:48.220 -0400 INFO TcpOutputProc - Closing stream for idx=X.X.X.X:9997 08-11-2016 07:07:48.220 -0400 INFO TcpOutputProc - Connected to idx=X.X.X.X:9997 08-11-2016 07:08:17.406 -0400 INFO TcpOutputProc - Closing stream for idx=X.X.X.X:9997 08-11-2016 07:08:17.406 -0400 INFO TcpOutputProc - Connected to idx=X.X.X.X:9997 08-11-2016 07:08:47.566 -0400 INFO TcpOutputProc - Closing stream for idx=X.X.X.X:9997 08-11-2016 07:08:47.566 -0400 INFO TcpOutputProc - Connected to idx=X.X.X.X:9997 08-11-2016 07:08:52.863 -0400 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-nessus/bin/nessus2splunk.py" usage: nessus2splunk.py [-h] [-s SRCDIR] [-t TGTDIR] 08-11-2016 07:08:52.863 -0400 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-nessus/bin/nessus2splunk.py" nessus2splunk.py: error: argument -s/--srcdir: Invalid path specified ($SPLUNK_HOME may not be set). 08-11-2016 07:09:17.565 -0400 INFO TcpOutputProc - Closing stream for idx=X.X.X.45:9997 08-11-2016 07:09:17.565 -0400 INFO TcpOutputProc - Connected to idx=X.X.X.X:9997 08-11-2016 07:09:47.859 -0400 INFO TcpOutputProc - Closing stream for idx=X.X.X.X:9997 08-11-2016 07:09:47.958 -0400 INFO TcpOutputProc - Connected to idx=X.X.X.X:9997 08-11-2016 07:10:18.029 -0400 INFO TcpOutputProc - Closing stream for idx=X.X.X.X:9997 08-11-2016 07:10:18.029 -0400 INFO TcpOutputProc - Connected to idx=X.X.X.X:9997 But after restarting the splunk service , I am able to get the output using the above query but it last for few min then again, there will not any data for index =_internal. Kindly guide me on this to fix the issue.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>