<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunkd is not working in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunkd-is-not-working/m-p/518401#M3309</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/201110"&gt;@niketn&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/1406"&gt;@woodcock&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/57922"&gt;@efika&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please help on above issue.&lt;/P&gt;</description>
    <pubDate>Tue, 08 Sep 2020 09:57:54 GMT</pubDate>
    <dc:creator>Javoraqa</dc:creator>
    <dc:date>2020-09-08T09:57:54Z</dc:date>
    <item>
      <title>Splunkd is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunkd-is-not-working/m-p/518287#M3281</link>
      <description>&lt;P&gt;&lt;SPAN&gt;[bin]$ ./splunk start&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;P&gt;Splunk&amp;gt; Like an F-18, bro.&lt;/P&gt;&lt;P&gt;Checking prerequisites...&lt;/P&gt;&lt;P&gt;Checking http port [8000]: open&lt;/P&gt;&lt;P&gt;Checking mgmt port [8089]: open&lt;/P&gt;&lt;P&gt;Checking appserver port [127.0.0.1:8065]: open&lt;/P&gt;&lt;P&gt;Checking kvstore port [8191]: open&lt;/P&gt;&lt;P&gt;Checking configuration... Done.&lt;/P&gt;&lt;P&gt;Checking critical directories... Done&lt;/P&gt;&lt;P&gt;Checking indexes... Validated: _audit _internal _introspection _metrics _metrics_rollup _telemetry _thefishbucket add_on_builder_index analysis_meta aws_db_status captain_america databricks_hec_webhook databricks_sqs_s3 databricks_webhook databricksjobruns databricksjobs dl_cluster em_meta em_metrics history infra_alerts iron_man2 main mysql1 platform_versions rss_feed summary talend_error tmc_info_warn trackme_metrics trackme_summary Done&lt;/P&gt;&lt;P&gt;Checking filesystem compatibility... Done Checking conf files for problems...&lt;/P&gt;&lt;P&gt;Invalid key in stanza [email] in /home/******/splunk/etc/apps/search/local/alert_actions.conf, line 2: show_password (value: True). Invalid key in stanza [mariadb] in /home/******/splunk/etc/apps/splunk_app_db_connect/default/db_connection_types.conf, line 240: supportedMajorVersion (value: 3). Invalid key in stanza [mariadb] in /home/******/splunk/etc/apps/splunk_app_db_connect/default/db_connection_types.conf, line 241: supportedMinorVersion (value: 1).&lt;/P&gt;&lt;P&gt;Your indexes and inputs configurations are not internally consistent. For more information, run 'splunk btool check --debug' Done Checking default conf files for edits...&lt;/P&gt;&lt;P&gt;Validating installed files against hashes from '/home/******/splunk/splunk-8.0.5-a1a6394cc5ae-linux-2.6-x86_64-manifest' All installed files intact. Done All preliminary checks passed.&lt;/P&gt;&lt;P&gt;Starting splunk server daemon (splunkd)... Done [ OK ]&lt;/P&gt;&lt;P&gt;Waiting for web server at &lt;A title="http://127.0.0.1:8000" href="http://127.0.0.1:8000" target="_blank" rel="noopener"&gt;http://127.0.0.1:8000&lt;/A&gt; to be available..................................................splunkd 18464 was not running.&lt;/P&gt;&lt;P&gt;Stopping splunk helpers... [ OK ] Done.&lt;/P&gt;&lt;P&gt;Stopped helpers. Removing stale pid file... done.&lt;/P&gt;&lt;P&gt;WARNING: web interface does not seem to be available!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have checked splunkd.log file but still cant figure out what is the error which is not allowing to start the splunk daemon&lt;/P&gt;&lt;P&gt;Can someone please help on above issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp; help needed&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 07 Sep 2020 18:47:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunkd-is-not-working/m-p/518287#M3281</guid>
      <dc:creator>Javoraqa</dc:creator>
      <dc:date>2020-09-07T18:47:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunkd is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunkd-is-not-working/m-p/518291#M3282</link>
      <description>&lt;P&gt;Can you paste at least ERROR and WARN entries from your splunkd.log (after My GUID is)?&lt;BR /&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Mon, 07 Sep 2020 18:50:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunkd-is-not-working/m-p/518291#M3282</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-09-07T18:50:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunkd is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunkd-is-not-working/m-p/518294#M3283</link>
      <description>&lt;P&gt;09-07-2020 04:29:01.635 -0700 WARN outputcsv - sid:scheduler_c3BsdW5rLXN5c3RlbS11c2Vy_c3BsdW5rX2FwcF9pbmZyYXN0cnVjdHVyZQ__RMD596ce4d2fa27924d1_at_1599478140_27360 Found no results to append to collection 'em_entity_cache'.&lt;BR /&gt;09-07-2020 04:29:17.497 -0700 WARN LocalAppsAdminHandler - Using deprecated capabilities for write: admin_all_objects or edit_local_apps. See enable_install_apps in limits.conf&lt;BR /&gt;09-07-2020 04:29:38.814 -0700 INFO IndexerIf - reloading index config: request received&lt;BR /&gt;09-07-2020 04:29:38.956 -0700 INFO DatabaseDirectoryManager - Start-up refreshing bucket manifest index=warn_logs&lt;BR /&gt;09-07-2020 04:29:38.957 -0700 INFO DatabaseDirectoryManager - idx=warn_logs Writing a bucket manifest in hotWarmPath='/home/*****/splunk/var/lib/splunk/warn_logs/db', pendingBucketUpdates=0 . Reason='Refreshing manifest at start-up.'&lt;BR /&gt;09-07-2020 04:29:38.965 -0700 INFO DatabaseDirectoryManager - Finished writing bucket manifest in hotWarmPath=/home/*****/splunk/var/lib/splunk/warn_logs/db&lt;BR /&gt;09-07-2020 04:29:38.965 -0700 INFO IndexProcessor - reloading index config: start&lt;BR /&gt;09-07-2020 04:29:38.965 -0700 INFO IndexProcessor - request state change from=RUN to=RECONFIGURING&lt;BR /&gt;09-07-2020 04:29:38.965 -0700 INFO IndexProcessor - Initializing: readonly=false reloading=true&lt;BR /&gt;09-07-2020 04:29:38.965 -0700 INFO IndexProcessor - Got a list of count=1 added, modified, or removed indexes&lt;BR /&gt;09-07-2020 04:29:38.965 -0700 INFO IndexProcessor - Reloading index config: shutdown subordinate threads, now restarting&lt;BR /&gt;09-07-2020 04:29:38.965 -0700 INFO HotDBManager - idx=warn_logs minHotIdleSecsBeforeForceRoll=auto; initializing, current value=600&lt;BR /&gt;09-07-2020 04:29:38.965 -0700 INFO HotDBManager - idx=warn_logs Setting hot mgr params: maxHotSpanSecs=7776000 maxHotBuckets=3 minHotIdleSecsBeforeForceRoll=auto maxDataSizeBytes=786432000 quarantinePastSecs=77760000 quarantineFutureSecs=2592000&lt;BR /&gt;09-07-2020 04:29:38.965 -0700 INFO HotDBManager - closing hot mgr for idx=warn_logs&lt;BR /&gt;09-07-2020 04:29:38.965 -0700 INFO IndexWriter - idx=warn_logs, Initializing,&lt;BR /&gt;09-07-2020 04:29:38.966 -0700 INFO IndexWriter - openDatabases complete currentId=-1 idx=warn_logs&lt;BR /&gt;09-07-2020 04:29:38.966 -0700 INFO IndexProcessor - Initializing indexes took usec=116 reloading=true indexes_initialized=1&lt;BR /&gt;09-07-2020 04:29:38.966 -0700 INFO IndexProcessor - request state change from=RECONFIGURING to=RUN&lt;BR /&gt;09-07-2020 04:29:38.966 -0700 INFO IndexProcessor - reloading index config: end&lt;BR /&gt;09-07-2020 04:30:01.385 -0700 WARN outputcsv - sid:scheduler_c3BsdW5rLXN5c3RlbS11c2Vy_c3BsdW5rX2FwcF9pbmZyYXN0cnVjdHVyZQ__RMD5087bf7ab8bb80e59_at_1599478200_27362 Found no results to append to collection 'em_entity_cache'.&lt;BR /&gt;09-07-2020 04:30:42.249 -0700 INFO IndexProcessor - handleSignal : Disabling streaming searches.&lt;BR /&gt;09-07-2020 04:30:42.249 -0700 INFO IndexProcessor - request state change from=RUN to=SHUTDOWN_SIGNALED&lt;BR /&gt;09-07-2020 04:30:42.249 -0700 INFO UiHttpListener - Shutting down webui&lt;BR /&gt;09-07-2020 04:30:42.263 -0700 INFO UiHttpListener - Shutting down webui completed&lt;BR /&gt;09-07-2020 04:30:42.538 -0700 INFO IndexProcessor - ingest_pipe=0: active realtime streams have hit 0 during shutdown&lt;BR /&gt;09-07-2020 04:30:47.304 -0700 INFO loader - Shutdown HTTPDispatchThread&lt;BR /&gt;09-07-2020 04:30:47.304 -0700 INFO ShutdownHandler - Shutting down splunkd&lt;BR /&gt;09-07-2020 04:30:47.304 -0700 INFO ShutdownHandler - shutting down level "ShutdownLevel_Begin"&lt;BR /&gt;09-07-2020 04:30:47.326 -0700 INFO ShutdownHandler - shutting down level "ShutdownLevel_FileIntegrityChecker"&lt;BR /&gt;09-07-2020 04:30:47.326 -0700 INFO ShutdownHandler - shutting down level "ShutdownLevel_JustBeforeKVStore"&lt;BR /&gt;09-07-2020 04:30:47.336 -0700 INFO ShutdownHandler - shutting down level "ShutdownLevel_KVStore"&lt;BR /&gt;09-07-2020 04:30:48.326 -0700 INFO ShutdownHandler - shutting down level "ShutdownLevel_DFM"&lt;BR /&gt;09-07-2020 04:30:48.326 -0700 INFO ShutdownHandler - shutting down level "ShutdownLevel_Thruput"&lt;BR /&gt;09-07-2020 04:30:48.326 -0700 INFO ShutdownHandler - shutting down level "ShutdownLevel_TcpInput1"&lt;BR /&gt;09-07-2020 04:30:48.326 -0700 INFO TcpInputProc - Running shutdown level 1. Closing listening ports.&lt;BR /&gt;09-07-2020 04:30:48.326 -0700 INFO TcpInputProc - Done setting shutdown in progress signal.&lt;BR /&gt;09-07-2020 04:30:48.326 -0700 INFO TcpInputProc - Shutting down listening ports&lt;BR /&gt;09-07-2020 04:30:48.326 -0700 INFO TcpInputProc - Stopping IPv4 port 9997&lt;BR /&gt;09-07-2020 04:30:48.326 -0700 INFO TcpInputProc - Setting up input quiesce timeout for : 90.000 secs&lt;BR /&gt;09-07-2020 04:30:49.006 -0700 INFO TcpInputProc - Waiting for connection from src=172.22.4.45:38090 to close before shutting down TcpInputProcessor.&lt;BR /&gt;09-07-2020 04:30:57.370 -0700 ERROR ExecProcessor - message from "/home/*****/splunk/bin/python2.7 /home/*****/splunk/etc/apps/webhooks_input/bin/webhook.py" 172.22.164.90 - - [07/Sep/2020 04:30:57] "GET /en-US/splunkd/__raw/services/messages?output_mode=json&amp;amp;sort_key=timeCreated_epochSecs&amp;amp;sort_dir=desc&amp;amp;count=1000&amp;amp;_=1599478173857 HTTP/1.1" 404 -&lt;BR /&gt;09-07-2020 04:30:57.370 -0700 ERROR ExecProcessor - message from "/home/*****/splunk/bin/python2.7 /home/*****/splunk/etc/apps/webhooks_input/bin/webhook.py" 172.22.164.90 - - [07/Sep/2020 04:30:57] "GET /en-US/splunkd/__raw/services/messages?output_mode=json&amp;amp;sort_key=timeCreated_epochSecs&amp;amp;sort_dir=desc&amp;amp;count=1000&amp;amp;_=1599478178555 HTTP/1.1" 404 -&lt;BR /&gt;09-07-2020 04:30:57.564 -0700 ERROR ExecProcessor - message from "/home/*****/splunk/bin/python2.7&lt;BR /&gt;allow Empty/Default cluster pass4symmkey=true rrt=restart dft=180 abt=600 sbs=1&lt;BR /&gt;09-07-2020 04:33:26.391 -0700 INFO ClusteringMgr - clustering disabled&lt;BR /&gt;09-07-2020 04:33:26.391 -0700 WARN SHCConfig - Default pass4symkey is being used. Please change to a random one.&lt;BR /&gt;09-07-2020 04:33:26.392 -0700 INFO SHClusterMgr - initing shpooling with: ht=60.000 rf=3 ct=60.000 st=60.000 rt=60.000 rct=5.000 rst=5.000 rrt=10.000 rmst=600.000 rmrt=600.000 pe=1 im=0 is=0 mor=5 pb=5 rep_port= pptr=10&lt;BR /&gt;09-07-2020 04:33:26.392 -0700 INFO SHClusterMgr - shpooling disabled&lt;BR /&gt;09-07-2020 04:33:26.420 -0700 WARN WorkloadConfig - Failed to read workload-pools in the workload_pools.conf file. There are no workload-pool stanzas.&lt;BR /&gt;09-07-2020 04:33:26.420 -0700 INFO WorkloadManager - Workload management for splunk node=******.*****.com with guid=59453183-4D77-48F9-BDC4-5D6276DB2690 has been disabled.&lt;BR /&gt;09-07-2020 04:33:26.423 -0700 INFO ulimit - Limit: data file size: unlimited&lt;BR /&gt;09-07-2020 04:33:26.423 -0700 INFO ulimit - Limit: open files: 4096 files&lt;BR /&gt;09-07-2020 04:33:26.423 -0700 INFO ulimit - Limit: user processes: 14993 processes&lt;BR /&gt;09-07-2020 04:33:26.423 -0700 INFO ulimit - Limit: cpu time: unlimited&lt;BR /&gt;09-07-2020 04:33:26.423 -0700 INFO ulimit - Linux transparent hugepage support, enabled="always" defrag="madvise"&lt;BR /&gt;09-07-2020 04:33:26.423 -0700 WARN ulimit - This configuration of transparent hugepages is known to cause serious runtime problems with Splunk. Typical symptoms include generally reduced performance and catastrophic breakdown in system responsiveness under high memory pressure. Please fix by setting the values for transparent huge pages to "madvise" or preferably "never" via sysctl, kernel boot parameters, or other method recommended by your Linux distribution.&lt;BR /&gt;&lt;BR /&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Sep 2020 19:02:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunkd-is-not-working/m-p/518294#M3283</guid>
      <dc:creator>Javoraqa</dc:creator>
      <dc:date>2020-09-07T19:02:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunkd is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunkd-is-not-working/m-p/518295#M3284</link>
      <description>&lt;P&gt;Have you configured systemd based boot start? And have you updated recently your index &amp;nbsp;definitions?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Sep 2020 19:18:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunkd-is-not-working/m-p/518295#M3284</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-09-07T19:18:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunkd is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunkd-is-not-working/m-p/518303#M3285</link>
      <description>&lt;P&gt;&lt;EM&gt;&lt;SPAN&gt;Have you configured systemd based boot start? And have you updated recently your index &lt;/SPAN&gt;&lt;/EM&gt;&amp;nbsp;definitions?&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I haven't configured any boot start configuration.&lt;/P&gt;&lt;P&gt;And last time I created index from UI i.e. warn_logs was the index name last I created.&lt;/P&gt;&lt;P&gt;Also I was trying to send logs using universal forwarder from remote server.&lt;/P&gt;&lt;P&gt;And created configuration in&lt;/P&gt;&lt;P&gt;&amp;nbsp;/etc/system/local/inputs.conf&lt;/P&gt;&lt;P&gt;Sending data from directory to my receiver.&lt;/P&gt;&lt;P&gt;In conf file I added monitor, index, sourcetype.&lt;/P&gt;&lt;P&gt;&amp;nbsp; Then I restarted UF everything was fine and using splunk list monitor I can see my log file were picked up by universal forwarder.&lt;/P&gt;&lt;P&gt;After that, I created manually same index as given in conf file in Splunk UI&lt;/P&gt;&lt;P&gt;Then restarted the splunk enterprise it gave me above error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Sep 2020 19:59:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunkd-is-not-working/m-p/518303#M3285</guid>
      <dc:creator>Javoraqa</dc:creator>
      <dc:date>2020-09-07T19:59:40Z</dc:date>
    </item>
    <item>
      <title>Re: Splunkd is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunkd-is-not-working/m-p/518352#M3296</link>
      <description>It’s quite big change that there is mistake/typo in your indexes.conf file. Can you post it here?</description>
      <pubDate>Tue, 08 Sep 2020 06:02:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunkd-is-not-working/m-p/518352#M3296</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-09-08T06:02:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunkd is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunkd-is-not-working/m-p/518387#M3301</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I haven't done any changes in default directory,&lt;/P&gt;&lt;P&gt;PFB indexes.conf file&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;################################################################################&lt;BR /&gt;# "global" params (not specific to individual indexes)&lt;BR /&gt;################################################################################&lt;BR /&gt;sync = 0&lt;BR /&gt;indexThreads = auto&lt;BR /&gt;memPoolMB = auto&lt;BR /&gt;defaultDatabase = main&lt;BR /&gt;enableRealtimeSearch = true&lt;BR /&gt;suppressBannerList =&lt;BR /&gt;maxRunningProcessGroups = 8&lt;BR /&gt;maxRunningProcessGroupsLowPriority = 1&lt;BR /&gt;bucketRebuildMemoryHint = auto&lt;BR /&gt;serviceOnlyAsNeeded = true&lt;BR /&gt;serviceSubtaskTimingPeriod = 30&lt;BR /&gt;serviceInactiveIndexesPeriod = 60&lt;BR /&gt;maxBucketSizeCacheEntries = 0&lt;BR /&gt;processTrackerServiceInterval = 1&lt;BR /&gt;hotBucketTimeRefreshInterval = 10&lt;BR /&gt;rtRouterThreads = 0&lt;BR /&gt;rtRouterQueueSize = 10000&lt;BR /&gt;selfStorageThreads = 2&lt;BR /&gt;fileSystemExecutorWorkers = 5&lt;/P&gt;&lt;P&gt;################################################################################&lt;BR /&gt;# index specific defaults&lt;BR /&gt;################################################################################&lt;BR /&gt;maxDataSize = auto&lt;BR /&gt;maxWarmDBCount = 300&lt;BR /&gt;frozenTimePeriodInSecs = 188697600&lt;BR /&gt;rotatePeriodInSecs = 60&lt;BR /&gt;coldToFrozenScript =&lt;BR /&gt;coldToFrozenDir =&lt;BR /&gt;compressRawdata = true&lt;BR /&gt;maxTotalDataSizeMB = 500000&lt;BR /&gt;maxGlobalRawDataSizeMB = 0&lt;BR /&gt;maxGlobalDataSizeMB = 0&lt;BR /&gt;maxMemMB = 5&lt;BR /&gt;maxConcurrentOptimizes = 6&lt;BR /&gt;maxHotSpanSecs = 7776000&lt;BR /&gt;maxHotIdleSecs = 0&lt;BR /&gt;maxHotBuckets = 3&lt;BR /&gt;minHotIdleSecsBeforeForceRoll = auto&lt;BR /&gt;quarantinePastSecs = 77760000&lt;BR /&gt;quarantineFutureSecs = 2592000&lt;BR /&gt;rawChunkSizeBytes = 131072&lt;BR /&gt;minRawFileSyncSecs = disable&lt;BR /&gt;assureUTF8 = false&lt;BR /&gt;serviceMetaPeriod = 25&lt;BR /&gt;partialServiceMetaPeriod = 0&lt;BR /&gt;throttleCheckPeriod = 15&lt;BR /&gt;syncMeta = true&lt;BR /&gt;maxMetaEntries = 1000000&lt;BR /&gt;maxBloomBackfillBucketAge = 30d&lt;BR /&gt;enableOnlineBucketRepair = true&lt;BR /&gt;enableDataIntegrityControl = false&lt;BR /&gt;maxTimeUnreplicatedWithAcks = 60&lt;BR /&gt;maxTimeUnreplicatedNoAcks = 300&lt;BR /&gt;minStreamGroupQueueSize = 2000&lt;BR /&gt;warmToColdScript=&lt;BR /&gt;tstatsHomePath = volume:_splunk_summaries/$_index_name/datamodel_summary&lt;BR /&gt;homePath.maxDataSizeMB = 0&lt;BR /&gt;coldPath.maxDataSizeMB = 0&lt;BR /&gt;streamingTargetTsidxSyncPeriodMsec = 5000&lt;BR /&gt;journalCompression = gzip&lt;BR /&gt;enableTsidxReduction = false&lt;BR /&gt;suspendHotRollByDeleteQuery = false&lt;BR /&gt;tsidxReductionCheckPeriodInSec = 600&lt;BR /&gt;timePeriodInSecBeforeTsidxReduction = 604800&lt;BR /&gt;datatype = event&lt;BR /&gt;splitByIndexKeys =&lt;BR /&gt;tsidxWritingLevel = 1&lt;BR /&gt;archiver.enableDataArchive = false&lt;BR /&gt;archiver.maxDataArchiveRetentionPeriod = 0&lt;BR /&gt;tsidxTargetSizeMB = 1500&lt;BR /&gt;metric.tsidxTargetSizeMB = 1500&lt;BR /&gt;metric.enableFloatingPointCompression = true&lt;BR /&gt;metric.compressionBlockSize = 1024&lt;BR /&gt;waitPeriodInSecsForManifestWrite = 60&lt;/P&gt;&lt;P&gt;#&lt;BR /&gt;# By default none of the indexes are replicated.&lt;BR /&gt;#&lt;BR /&gt;repFactor = 0&lt;/P&gt;&lt;P&gt;[volume:_splunk_summaries]&lt;BR /&gt;path = $SPLUNK_DB&lt;/P&gt;&lt;P&gt;[provider-family:hadoop]&lt;BR /&gt;vix.mode = report&lt;BR /&gt;vix.command = $SPLUNK_HOME/bin/jars/sudobash&lt;BR /&gt;vix.command.arg.1 = $HADOOP_HOME/bin/hadoop&lt;BR /&gt;vix.command.arg.2 = jar&lt;BR /&gt;vix.command.arg.3 = $SPLUNK_HOME/bin/jars/SplunkMR-h1.jar&lt;BR /&gt;vix.command.arg.4 = com.splunk.mr.SplunkMR&lt;BR /&gt;vix.env.MAPREDUCE_USER =&lt;BR /&gt;vix.env.HADOOP_HEAPSIZE = 512&lt;BR /&gt;vix.env.HADOOP_CLIENT_OPTS = -XX:ParallelGCThreads=4 -XX:+UseParallelGC -XX:+DisplayVMOutputToStderr&lt;BR /&gt;vix.env.HUNK_THIRDPARTY_JARS = $SPLUNK_HOME/bin/jars/thirdparty/common/avro-1.7.7.jar,$SPLUNK_HOME/bin/jars/thirdparty/common/avro-mapred-1.7.7.jar,$SPLUNK_HOME/bin/jars/thirdparty/common/commons-compress-1.19.jar,$SPLUNK_HOME/bin/jars/thirdparty/common/commons-io-2.4.jar,$SPLUNK_HOME/bin/jars/thirdparty/common/libfb303-0.9.2.jar,$SPLUNK_HOME/bin/jars/thirdparty/common/parquet-hive-bundle-1.10.1.jar,$SPLUNK_HOME/bin/jars/thirdparty/common/snappy-java-1.1.1.7.jar,$SPLUNK_HOME/bin/jars/thirdparty/hive/hive-exec-0.12.0.jar,$SPLUNK_HOME/bin/jars/thirdparty/hive/hive-metastore-0.12.0.jar,$SPLUNK_HOME/bin/jars/thirdparty/hive/hive-serde-0.12.0.jar&lt;BR /&gt;vix.mapred.job.reuse.jvm.num.tasks = 100&lt;BR /&gt;vix.mapred.child.java.opts = -server -Xmx512m -XX:ParallelGCThreads=4 -XX:+UseParallelGC -XX:+DisplayVMOutputToStderr&lt;BR /&gt;vix.mapred.reduce.tasks = 0&lt;BR /&gt;vix.mapred.job.map.memory.mb = 2048&lt;BR /&gt;vix.mapred.job.reduce.memory.mb = 512&lt;BR /&gt;vix.mapred.job.queue.name = default&lt;BR /&gt;vix.mapreduce.job.jvm.numtasks = 100&lt;BR /&gt;vix.mapreduce.map.java.opts = -server -Xmx512m -XX:ParallelGCThreads=4 -XX:+UseParallelGC -XX:+DisplayVMOutputToStderr&lt;BR /&gt;vix.mapreduce.reduce.java.opts = -server -Xmx512m -XX:ParallelGCThreads=4 -XX:+UseParallelGC -XX:+DisplayVMOutputToStderr&lt;BR /&gt;vix.mapreduce.job.reduces = 0&lt;BR /&gt;vix.mapreduce.map.memory.mb = 2048&lt;BR /&gt;vix.mapreduce.reduce.memory.mb = 512&lt;BR /&gt;vix.mapreduce.job.queuename = default&lt;BR /&gt;vix.splunk.search.column.filter = 1&lt;BR /&gt;vix.splunk.search.mixedmode = 1&lt;BR /&gt;vix.splunk.search.debug = 0&lt;BR /&gt;vix.splunk.search.mr.maxsplits = 10000&lt;BR /&gt;vix.splunk.search.mr.minsplits = 100&lt;BR /&gt;vix.splunk.search.mr.splits.multiplier = 10&lt;BR /&gt;vix.splunk.search.mr.poll = 2000&lt;BR /&gt;vix.splunk.search.recordreader = SplunkJournalRecordReader,ValueAvroRecordReader,SimpleCSVRecordReader,SequenceFileRecordReader&lt;BR /&gt;vix.splunk.search.recordreader.avro.regex = \.avro$&lt;BR /&gt;vix.splunk.search.recordreader.csv.regex = \.([tc]sv)(?:\.(?:gz|bz2|snappy))?$&lt;BR /&gt;vix.splunk.search.recordreader.sequence.regex = \.seq$&lt;BR /&gt;vix.splunk.home.datanode = /tmp/splunk/$SPLUNK_SERVER_NAME/&lt;BR /&gt;vix.splunk.heartbeat = 1&lt;BR /&gt;vix.splunk.heartbeat.threshold = 60&lt;BR /&gt;vix.splunk.heartbeat.interval = 1000&lt;BR /&gt;vix.splunk.setup.onsearch = 1&lt;BR /&gt;vix.splunk.setup.package = current&lt;/P&gt;&lt;P&gt;################################################################################&lt;BR /&gt;# index definitions&lt;BR /&gt;################################################################################&lt;/P&gt;&lt;P&gt;[main]&lt;BR /&gt;homePath = $SPLUNK_DB/defaultdb/db&lt;BR /&gt;coldPath = $SPLUNK_DB/defaultdb/colddb&lt;BR /&gt;thawedPath = $SPLUNK_DB/defaultdb/thaweddb&lt;BR /&gt;tstatsHomePath = volume:_splunk_summaries/defaultdb/datamodel_summary&lt;BR /&gt;maxMemMB = 20&lt;BR /&gt;maxConcurrentOptimizes = 6&lt;BR /&gt;maxHotIdleSecs = 86400&lt;BR /&gt;maxHotBuckets = 10&lt;BR /&gt;maxDataSize = auto_high_volume&lt;/P&gt;&lt;P&gt;[history]&lt;BR /&gt;homePath = $SPLUNK_DB/historydb/db&lt;BR /&gt;coldPath = $SPLUNK_DB/historydb/colddb&lt;BR /&gt;thawedPath = $SPLUNK_DB/historydb/thaweddb&lt;BR /&gt;tstatsHomePath = volume:_splunk_summaries/historydb/datamodel_summary&lt;BR /&gt;maxDataSize = 10&lt;BR /&gt;frozenTimePeriodInSecs = 604800&lt;/P&gt;&lt;P&gt;[summary]&lt;BR /&gt;homePath = $SPLUNK_DB/summarydb/db&lt;BR /&gt;coldPath = $SPLUNK_DB/summarydb/colddb&lt;BR /&gt;thawedPath = $SPLUNK_DB/summarydb/thaweddb&lt;BR /&gt;tstatsHomePath = volume:_splunk_summaries/summarydb/datamodel_summary&lt;/P&gt;&lt;P&gt;[_internal]&lt;BR /&gt;homePath = $SPLUNK_DB/_internaldb/db&lt;BR /&gt;coldPath = $SPLUNK_DB/_internaldb/colddb&lt;BR /&gt;thawedPath = $SPLUNK_DB/_internaldb/thaweddb&lt;BR /&gt;tstatsHomePath = volume:_splunk_summaries/_internaldb/datamodel_summary&lt;BR /&gt;maxDataSize = 1000&lt;BR /&gt;maxHotSpanSecs = 432000&lt;BR /&gt;frozenTimePeriodInSecs = 2592000&lt;/P&gt;&lt;P&gt;[_audit]&lt;BR /&gt;homePath = $SPLUNK_DB/audit/db&lt;BR /&gt;coldPath = $SPLUNK_DB/audit/colddb&lt;BR /&gt;thawedPath = $SPLUNK_DB/audit/thaweddb&lt;BR /&gt;tstatsHomePath = volume:_splunk_summaries/audit/datamodel_summary&lt;/P&gt;&lt;P&gt;[_thefishbucket]&lt;BR /&gt;homePath = $SPLUNK_DB/fishbucket/db&lt;BR /&gt;coldPath = $SPLUNK_DB/fishbucket/colddb&lt;BR /&gt;thawedPath = $SPLUNK_DB/fishbucket/thaweddb&lt;BR /&gt;tstatsHomePath = volume:_splunk_summaries/fishbucket/datamodel_summary&lt;BR /&gt;maxDataSize = 500&lt;BR /&gt;frozenTimePeriodInSecs = 2419200&lt;/P&gt;&lt;P&gt;# this index has been removed in the 4.1 series, but this stanza must be&lt;BR /&gt;# preserved to avoid displaying errors for users that have tweaked the index's&lt;BR /&gt;# size/etc parameters in local/indexes.conf.&lt;BR /&gt;#&lt;BR /&gt;[splunklogger]&lt;BR /&gt;homePath = $SPLUNK_DB/splunklogger/db&lt;BR /&gt;coldPath = $SPLUNK_DB/splunklogger/colddb&lt;BR /&gt;thawedPath = $SPLUNK_DB/splunklogger/thaweddb&lt;BR /&gt;disabled = true&lt;/P&gt;&lt;P&gt;[_introspection]&lt;BR /&gt;homePath = $SPLUNK_DB/_introspection/db&lt;BR /&gt;coldPath = $SPLUNK_DB/_introspection/colddb&lt;BR /&gt;thawedPath = $SPLUNK_DB/_introspection/thaweddb&lt;BR /&gt;maxDataSize = 1024&lt;BR /&gt;frozenTimePeriodInSecs = 1209600&lt;/P&gt;&lt;P&gt;[_telemetry]&lt;BR /&gt;homePath = $SPLUNK_DB/_telemetry/db&lt;BR /&gt;coldPath = $SPLUNK_DB/_telemetry/colddb&lt;BR /&gt;thawedPath = $SPLUNK_DB/_telemetry/thaweddb&lt;BR /&gt;maxDataSize = 256&lt;BR /&gt;frozenTimePeriodInSecs = 63072000&lt;/P&gt;&lt;P&gt;[_metrics]&lt;BR /&gt;homePath = $SPLUNK_DB/_metrics/db&lt;BR /&gt;coldPath = $SPLUNK_DB/_metrics/colddb&lt;BR /&gt;thawedPath = $SPLUNK_DB/_metrics/thaweddb&lt;BR /&gt;datatype = metric&lt;BR /&gt;#14 day retention&lt;BR /&gt;frozenTimePeriodInSecs = 1209600&lt;BR /&gt;splitByIndexKeys = metric_name&lt;/P&gt;&lt;P&gt;# Internal Use Only: rollup data from the _metrics index.&lt;BR /&gt;[_metrics_rollup]&lt;BR /&gt;homePath = $SPLUNK_DB/_metrics_rollup/db&lt;BR /&gt;coldPath = $SPLUNK_DB/_metrics_rollup/colddb&lt;BR /&gt;thawedPath = $SPLUNK_DB/_metrics_rollup/thaweddb&lt;BR /&gt;datatype = metric&lt;BR /&gt;# 2 year retention&lt;BR /&gt;frozenTimePeriodInSecs = 63072000&lt;BR /&gt;splitByIndexKeys = metric_name&lt;/P&gt;&lt;P&gt;# NOTE: When adding a new index, please also add an entry in cfg/bundles/cluster/default/indexes.conf.in&lt;BR /&gt;# with repFactor=0, homePath, coldPath, and thawedPath&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2020 08:26:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunkd-is-not-working/m-p/518387#M3301</guid>
      <dc:creator>Javoraqa</dc:creator>
      <dc:date>2020-09-08T08:26:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunkd is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunkd-is-not-working/m-p/518388#M3302</link>
      <description>&lt;P&gt;You said:&lt;/P&gt;&lt;LI-CODE lang="java"&gt;After that, I created manually same index as given in conf file in Splunk UI

Then restarted the splunk enterprise it gave me above error.&lt;/LI-CODE&gt;&lt;P&gt;I would like to see those changes.&lt;/P&gt;&lt;P&gt;r. Ismo&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2020 08:40:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunkd-is-not-working/m-p/518388#M3302</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-09-08T08:40:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunkd is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunkd-is-not-working/m-p/518389#M3303</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This was my inputs.conf file in UF path - etc/system/local/inputs.conf&lt;/P&gt;&lt;P&gt;[monitor:///data/*****/logs/]&lt;BR /&gt;disabled = 0&lt;BR /&gt;host = *****.******.com&lt;BR /&gt;index=warn_logs&lt;BR /&gt;sourcetype = *****_exceptions&lt;BR /&gt;whitelist = .+ERROR.+$&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2020 08:44:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunkd-is-not-working/m-p/518389#M3303</guid>
      <dc:creator>Javoraqa</dc:creator>
      <dc:date>2020-09-08T08:44:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunkd is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunkd-is-not-working/m-p/518391#M3304</link>
      <description>You don't change that indexes.conf on indexer side?</description>
      <pubDate>Tue, 08 Sep 2020 08:45:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunkd-is-not-working/m-p/518391#M3304</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-09-08T08:45:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunkd is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunkd-is-not-working/m-p/518392#M3305</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;No changes were done in indexes.conf file on indexer side.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2020 08:55:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunkd-is-not-working/m-p/518392#M3305</guid>
      <dc:creator>Javoraqa</dc:creator>
      <dc:date>2020-09-08T08:55:07Z</dc:date>
    </item>
    <item>
      <title>Re: Splunkd is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunkd-is-not-working/m-p/518401#M3309</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/201110"&gt;@niketn&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/1406"&gt;@woodcock&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/57922"&gt;@efika&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please help on above issue.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2020 09:57:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunkd-is-not-working/m-p/518401#M3309</guid>
      <dc:creator>Javoraqa</dc:creator>
      <dc:date>2020-09-08T09:57:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunkd is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunkd-is-not-working/m-p/518402#M3310</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i got some error logs from splunkd.log file, are this errors not allowing splunkd to restart&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;09-08-2020 00:52:18.877 -0700 ERROR BucketMover - Failed to create file='/home/*****/splunk/var/lib/splunk/audit/db/db_1599484818_1599484739_40/optimize.result': Permission denied&lt;BR /&gt;09-08-2020 00:52:18.879 -0700 ERROR BucketMover - Failed to create file='/home/*****/splunk/var/lib/splunk/_internaldb/db/db_1599484817_1599484682_41/optimize.result': Permission denied&lt;BR /&gt;09-08-2020 00:52:18.880 -0700 ERROR BucketMover - Failed to create file='/home/*****/splunk/var/lib/splunk/_introspection/db/db_1599484771_1599484678_40/optimize.result': Permission denied&lt;BR /&gt;09-08-2020 00:52:18.881 -0700 ERROR BucketMover - Failed to create file='/home/*****/splunk/var/lib/splunk/_metrics/db/db_1599484797_1599484678_81/optimize.result': Permission denied&lt;BR /&gt;09-08-2020 00:52:18.881 -0700 ERROR BucketMover - Failed to create file='/home/*****/splunk/var/lib/splunk/_metrics/db/db_1599484797_1599484678_80/optimize.result': Permission denied&lt;BR /&gt;09-08-2020 00:52:18.885 -0700 ERROR BucketMover - Failed to create file='/home/*****/splunk/var/lib/splunk/em_metrics/db/db_1599484799_1599484768_13/optimize.result': Permission denied&lt;BR /&gt;09-08-2020 00:52:18.886 -0700 ERROR BucketMover - Failed to create file='/home/*****/splunk/var/lib/splunk/defaultdb/db/db_1599484769_1599484768_28/optimize.result': Permission denied&lt;BR /&gt;09-08-2020 00:52:23.703 -0700 ERROR TailingProcessor - Skipping stanza 'batch://$SPLUNK_HOME\var\spool\splunk\...stash_syndication_input' due to error: Failed to regex-split wildcarded path: $SPLUNK_HOME\var\spool\splunk\...stash_syndication_input for stanza batch://$SPLUNK_HOME\var\spool\splunk\...stash_syndication_input..&lt;BR /&gt;09-08-2020 00:52:23.703 -0700 ERROR TailingProcessor - Skipping stanza 'batch://$SPLUNK_HOME\var\spool\splunk\...stash_web_input' due to error: Failed to regex-split wildcarded path: $SPLUNK_HOME\var\spool\splunk\...stash_web_input for stanza batch://$SPLUNK_HOME\var\spool\splunk\...stash_web_input..&lt;BR /&gt;09-08-2020 00:52:28.920 -0700 ERROR ExecProcessor - message from "/home/*****/splunk/bin/python2.7 /home/*****/splunk/etc/apps/webhooks_input/bin/webhook.py" 127.0.0.1 - - [08/Sep/2020 00:52:28] "HEAD /robots.txt HTTP/1.1" 404 -&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2020 11:25:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunkd-is-not-working/m-p/518402#M3310</guid>
      <dc:creator>Javoraqa</dc:creator>
      <dc:date>2020-09-08T11:25:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunkd is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunkd-is-not-working/m-p/518411#M3316</link>
      <description>Yep, I think so. Can you change the ownerships to those to user which are running splunk processes?</description>
      <pubDate>Tue, 08 Sep 2020 10:48:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunkd-is-not-working/m-p/518411#M3316</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-09-08T10:48:37Z</dc:date>
    </item>
    <item>
      <title>Re: Splunkd is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunkd-is-not-working/m-p/518430#M3317</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;Even after changing the ownership of files, still facing same issue&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;below are some updated logs&amp;nbsp;&lt;BR /&gt;09-08-2020 04:42:27.881 -0700 ERROR ExecProcessor - message from "/home/*****/splunk/bin/python2.7 /home/*****/splunk/etc/apps/webhooks_input/bin/webhook.py" 127.0.0.1 - - [08/Sep/2020 04:42:27] "HEAD /robots.txt HTTP/1.1" 404 -&lt;BR /&gt;09-08-2020 04:42:27.898 -0700 WARN outputcsv - sid:scheduler_c3BsdW5rLXN5c3RlbS11c2Vy_c3BsdW5rX2FwcF9pbmZyYXN0cnVjdHVyZQ__RMD51a41784832141e6b_at_1599565320_7 Found no results to append to collection 'em_entity_cache'.&lt;BR /&gt;09-08-2020 04:42:27.936 -0700 WARN outputcsv - sid:scheduler_c3BsdW5rLXN5c3RlbS11c2Vy_c3BsdW5rX2FwcF9pbmZyYXN0cnVjdHVyZQ__RMD596ce4d2fa27924d1_at_1599565320_8 Found no results to append to collection 'em_entity_cache'.&lt;BR /&gt;09-08-2020 04:42:27.937 -0700 FATAL HTTPServer - Could not bind to ip 127.0.0.1 port 8000&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2020 12:07:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunkd-is-not-working/m-p/518430#M3317</guid>
      <dc:creator>Javoraqa</dc:creator>
      <dc:date>2020-09-08T12:07:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunkd is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunkd-is-not-working/m-p/518467#M3327</link>
      <description>Could not bind to ip xx port yy, means that there are something already used that ip+port.&lt;BR /&gt;Can you check It with netstat -napt and check which process is bind to it.</description>
      <pubDate>Tue, 08 Sep 2020 15:15:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunkd-is-not-working/m-p/518467#M3327</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-09-08T15:15:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunkd is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunkd-is-not-working/m-p/519639#M3435</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;Issue is resolved, it was web-hook app which was creating issue.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 08:21:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunkd-is-not-working/m-p/519639#M3435</guid>
      <dc:creator>Javoraqa</dc:creator>
      <dc:date>2020-09-15T08:21:07Z</dc:date>
    </item>
  </channel>
</rss>

