<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk arbitrarily deletes index on restart in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-arbitrarily-deletes-index-on-restart/m-p/130402#M4924</link>
    <description>&lt;P&gt;What did you name the index? Does the name begin with an underscore?&lt;/P&gt;</description>
    <pubDate>Thu, 30 Jan 2014 06:15:55 GMT</pubDate>
    <dc:creator>lguinn2</dc:creator>
    <dc:date>2014-01-30T06:15:55Z</dc:date>
    <item>
      <title>Splunk arbitrarily deletes index on restart</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-arbitrarily-deletes-index-on-restart/m-p/130399#M4921</link>
      <description>&lt;P&gt;I have one particular index whose data gets deleted any time Splunk is restarted.  I see this in the splunkd.log:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;idx=my_index Removing; IP::deleteIndex
idx=my_index Removing; wait for in-flights
idx=my_index Removing; erasing DPP from lookups
idx=my_index Handling shutdown or signal, reason=3
idx=my_index Deletion approved, start dir removal
closing hot mgr for idx=my_index
idx=my_index Removing; erased directory='E:\Splunk\var\lib\splunk\my_index\db' (param=homePath)
idx=my_index Removing; erased directory='E:\Splunk\var\lib\splunk\my_index\colddb' (param=coldPath)
idx=my_index Removing; parameter=bloomHomePath has no assigned value
idx=my_index Removing; directory='E:\Splunk\var\lib\splunk\my_index\summary' (param=summaryHomePath) not found
idx=my_index Removing; parameter=tstatsHomePath has no assigned value
idx=my_index Removing; erased directory='E:\Splunk\var\lib\splunk\my_index\thaweddb' (param=thawedPath)
idx=my_index Removing; erased directory='E:\Splunk\var\lib\splunk\my_index' (param=index proper)
removing index=my_index stanza from indexes.conf app=my_app
idx=my_index Finished removing
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;When Splunk starts back up again, it goes through the process of creating everything that was just deleted.&lt;/P&gt;

&lt;P&gt;As far as I can tell, there are no differences between this index and any other index.  It was created through the Admin with the default settings, exactly the same way as every other index I've created.  There's nothing special about the data; we're indexing similar data in two other indexes which are unaffected by Splunk restarts (.csv data).&lt;/P&gt;

&lt;P&gt;Is there some setting hidden in a .conf file somewhere that I should look for?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2014 22:35:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-arbitrarily-deletes-index-on-restart/m-p/130399#M4921</guid>
      <dc:creator>redc</dc:creator>
      <dc:date>2014-01-29T22:35:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk arbitrarily deletes index on restart</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-arbitrarily-deletes-index-on-restart/m-p/130400#M4922</link>
      <description>&lt;P&gt;Two questions: &lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;Can you do a more general search in _index to see if there is anything specific initiating the request to delete the index? &lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;If you find no root cause in 1) , what happens if you actively delete the index, then restart, then recreate the index with the same name. Does the behavior persist?&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Wed, 29 Jan 2014 23:04:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-arbitrarily-deletes-index-on-restart/m-p/130400#M4922</guid>
      <dc:creator>mkinsley_splunk</dc:creator>
      <dc:date>2014-01-29T23:04:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk arbitrarily deletes index on restart</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-arbitrarily-deletes-index-on-restart/m-p/130401#M4923</link>
      <description>&lt;P&gt;What are the timestamps for the data you're sending to this index?&lt;BR /&gt;
What is the size of the data?&lt;BR /&gt;
Have you changed the default properties in &lt;CODE&gt;etc/system/local/indexes.conf&lt;/CODE&gt; or &lt;CODE&gt;default/indexes.conf&lt;/CODE&gt;?&lt;BR /&gt;
When you say 'recreate what was deleted' do you mean the file structure or the actual data?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2014 01:00:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-arbitrarily-deletes-index-on-restart/m-p/130401#M4923</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2014-01-30T01:00:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk arbitrarily deletes index on restart</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-arbitrarily-deletes-index-on-restart/m-p/130402#M4924</link>
      <description>&lt;P&gt;What did you name the index? Does the name begin with an underscore?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2014 06:15:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-arbitrarily-deletes-index-on-restart/m-p/130402#M4924</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2014-01-30T06:15:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk arbitrarily deletes index on restart</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-arbitrarily-deletes-index-on-restart/m-p/130403#M4925</link>
      <description>&lt;P&gt;@mkinsley_splunk:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;The log lines above came from _internal.  It appears to be initiated by the Splunk service restart.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;I'll give that a shot as soon as I can schedule it with the person using the data.&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Thu, 30 Jan 2014 16:01:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-arbitrarily-deletes-index-on-restart/m-p/130403#M4925</guid>
      <dc:creator>redc</dc:creator>
      <dc:date>2014-01-30T16:01:59Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk arbitrarily deletes index on restart</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-arbitrarily-deletes-index-on-restart/m-p/130404#M4926</link>
      <description>&lt;P&gt;@lukejadamec:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;The data falls between 2001 and 2004 (it's demo data generated by a really old program).  There is other data in the same date range that is in other indexes and is unaffected, so I don't think it's age-related.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Less than 1MB (305 events).  Related data is between 140 and 1,000 events (all under 1MB).&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;No, we haven't changed the properties manually.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Just the file structure.  That's why it's so frustrating because we then have to re-import the data.&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Thu, 30 Jan 2014 16:03:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-arbitrarily-deletes-index-on-restart/m-p/130404#M4926</guid>
      <dc:creator>redc</dc:creator>
      <dc:date>2014-01-30T16:03:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk arbitrarily deletes index on restart</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-arbitrarily-deletes-index-on-restart/m-p/130405#M4927</link>
      <description>&lt;P&gt;@Anonymous:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;"quick_rad_orderhistory".  The unaffected indexes all start with "quick_rad_".&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;No, no special characters or underscores or anything at the start of the index names.&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:46:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-arbitrarily-deletes-index-on-restart/m-p/130405#M4927</guid>
      <dc:creator>redc</dc:creator>
      <dc:date>2020-09-28T15:46:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk arbitrarily deletes index on restart</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-arbitrarily-deletes-index-on-restart/m-p/130406#M4928</link>
      <description>&lt;P&gt;The default for the age of data before it is frozen (deleted) is &lt;CODE&gt;frozenTimePeriodInSecs = 188697600&lt;/CODE&gt;, which is about 6 years.  In order for a bucket to get deleted, all data in the bucket must be older than the setting (about 6 years).  If the other indexes buckets also contain newer data (less than 6 years) then they would not be deleted.&lt;/P&gt;

&lt;P&gt;Try including some recent inputs into the index.&lt;/P&gt;

&lt;P&gt;You can check the newest and oldest event in a bucket by looking at the bucket name.  The two long numbers are epoch time stamps for the newest and oldest event in the bucket.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2014 16:13:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-arbitrarily-deletes-index-on-restart/m-p/130406#M4928</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2014-01-30T16:13:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk arbitrarily deletes index on restart</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-arbitrarily-deletes-index-on-restart/m-p/130407#M4929</link>
      <description>&lt;P&gt;We'll try that, but the other "quick_rad_" indexes don't have newer data in them, either, and they're not being affected.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:46:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-arbitrarily-deletes-index-on-restart/m-p/130407#M4929</guid>
      <dc:creator>redc</dc:creator>
      <dc:date>2020-09-28T15:46:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk arbitrarily deletes index on restart</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-arbitrarily-deletes-index-on-restart/m-p/130408#M4930</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/142276"&gt;@mkinsley_splunk&lt;/a&gt;:&lt;/P&gt;

&lt;P&gt;We deleted, restarted, and recreated the index.  We also updated the demo data to use more recent data.&lt;/P&gt;

&lt;P&gt;That seems to have fixed the issue, except...now one of the other indexes (also starting with "quick_rad_" and with older data) is now exhibiting this behavior.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:46:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-arbitrarily-deletes-index-on-restart/m-p/130408#M4930</guid>
      <dc:creator>redc</dc:creator>
      <dc:date>2020-09-28T15:46:40Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk arbitrarily deletes index on restart</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-arbitrarily-deletes-index-on-restart/m-p/130409#M4931</link>
      <description>&lt;P&gt;We set a frozen archive path on the affected index, re-imported the .csv data, and then restarted Splunk and it did create the frozen database archive under the frozen archive path.&lt;/P&gt;

&lt;P&gt;We'll just have to manually manipulate the demo data our program is spitting out to have more recent dates.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2014 21:00:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-arbitrarily-deletes-index-on-restart/m-p/130409#M4931</guid>
      <dc:creator>redc</dc:creator>
      <dc:date>2014-01-30T21:00:50Z</dc:date>
    </item>
  </channel>
</rss>

