deductiv / export_everything

Export Everything Add-On for Splunk
Apache License 2.0
11 stars 5 forks source link

CRITICAL Search terminated prematurely. No data was exported. #54

Open thormanrd opened 3 months ago

thormanrd commented 3 months ago

I’ve installed v2.4.0 for a SFTP transfer that has been running for months and now will not export. The runas user has all the capabilities mentioned in the splunkbase details. Every run ends with this log.

2024-04-15 13:45:38,102 search_ep_sftp[628582] CRITICAL Search terminated prematurely. No data was exported.

Without the | epsftp command the search produces the expected output.

export_everything_debug.log

jrzmurray commented 3 months ago

Hi Bob, what version of Splunk are you running? Did this run okay with a prior Splunk version, or Export Everything version? If so, which versions? Since this seems to think there is a terminated search, can you please send me the search.log file for the search you ran to export the data?

Also, please let me know if the Browse functionality to your configured SFTP server works for you in the App Setup page.

From: Bob Thorman @.> Date: Monday, April 15, 2024 at 2:50 PM To: deductiv/export_everything @.> Cc: Subscribed @.***> Subject: [deductiv/export_everything] CRITICAL Search terminated prematurely. No data was exported. (Issue #54)

I’ve installed v2.4.0 for a SFTP transfer that has been running for months and now will not export. The runas user has all the capabilities mentioned in the splunkbase details. Every run ends with this log.

2024-04-15 13:45:38,102 search_ep_sftp[628582] CRITICAL Search terminated prematurely. No data was exported.

Without the | epsftp command the search produces the expected output.

export_everything_debug.loghttps://github.com/deductiv/export_everything/files/14983184/export_everything_debug.log

— Reply to this email directly, view it on GitHubhttps://github.com/deductiv/export_everything/issues/54, or unsubscribehttps://github.com/notifications/unsubscribe-auth/AA7NPAUJDEUO5FPKX36Q2WDY5QOPZAVCNFSM6AAAAABGH4X7K2VHI2DSMVQWIX3LMV43ASLTON2WKOZSGI2DIMZYGYZTMMA. You are receiving this because you are subscribed to this thread.Message ID: @.***>

thormanrd commented 3 months ago

The current issue I'm having is on Splunk Enterprise v9.1.2 using Export Everything v2.4.0. Previously when it worked, I was on Splunk Enterprise v9.0.4 and Export Everything v2.2.2.

The search.log is attached and the browse does work under the SFTP configuration tab of the app. I've attached a screenshot of that.

[browse_sftp] (https://github.com/deductiv/export_everything/assets/7852536/127df265-6609-4224-94ab-2cd80852532e)

export_everything_search.log

thormanrd commented 3 months ago

@jrzmurray

I went back to my older system and updated keys and it still works there. See the attached screen shot showing the uploaded file in the browse window.

browse_with_file

thormanrd commented 2 months ago

@jrzmurray, any update on this issue? I reverted back to v2.2.2 on Splunk Enterprise v9.1.2 and it still does not work. Something about v9.1 EE doesn't like. Any help is appreciated.

thormanrd commented 1 month ago

Export Everything 2.4.0 opens the browse window with the credential I have loaded. But I still get this critical error and my upload is terminated. Any progress on this?

Screenshot 2024-05-30 at 7 41 54 AM Screenshot 2024-05-30 at 7 42 05 AM