<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic splunk fsck repair fails with &amp;quot;Process delayed by # seconds...&amp;quot; in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/splunk-fsck-repair-fails-with-quot-Process-delayed-by-seconds/m-p/574497#M101555</link>
    <description>&lt;P&gt;I recently performed a data migration to correct some mistakes made by the person who built our environment. Afterward, I found I had to run `splunk fsck repair` due to errors that are preventing splunk from starting. After running the command with "--all-buckets-all-indexes" or "--all-buckets-one-index --index-name=linux" it stops without seeming to do anything.&lt;/P&gt;&lt;P&gt;After it stops I get, as an example&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;Process delayed by 56.174 seconds, perhaps system was suspended?&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;Stopping WatchdogThread.&lt;/P&gt;&lt;P&gt;We have four indexers in a cluster. I've put the cluster master in maintenance mode and stopped splunk on all of the indexers. I'm running the command on a single indexer since the data is shared via NFS.&amp;nbsp;One thing I haven't done is unmount the share on all of the other indexers.&lt;/P&gt;&lt;P&gt;What is the cause of this error and what do I need to do to move past it?&lt;/P&gt;</description>
    <pubDate>Wed, 10 Nov 2021 21:18:04 GMT</pubDate>
    <dc:creator>snyderm_dos</dc:creator>
    <dc:date>2021-11-10T21:18:04Z</dc:date>
    <item>
      <title>splunk fsck repair fails with "Process delayed by # seconds..."</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-fsck-repair-fails-with-quot-Process-delayed-by-seconds/m-p/574497#M101555</link>
      <description>&lt;P&gt;I recently performed a data migration to correct some mistakes made by the person who built our environment. Afterward, I found I had to run `splunk fsck repair` due to errors that are preventing splunk from starting. After running the command with "--all-buckets-all-indexes" or "--all-buckets-one-index --index-name=linux" it stops without seeming to do anything.&lt;/P&gt;&lt;P&gt;After it stops I get, as an example&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;Process delayed by 56.174 seconds, perhaps system was suspended?&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;Stopping WatchdogThread.&lt;/P&gt;&lt;P&gt;We have four indexers in a cluster. I've put the cluster master in maintenance mode and stopped splunk on all of the indexers. I'm running the command on a single indexer since the data is shared via NFS.&amp;nbsp;One thing I haven't done is unmount the share on all of the other indexers.&lt;/P&gt;&lt;P&gt;What is the cause of this error and what do I need to do to move past it?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Nov 2021 21:18:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-fsck-repair-fails-with-quot-Process-delayed-by-seconds/m-p/574497#M101555</guid>
      <dc:creator>snyderm_dos</dc:creator>
      <dc:date>2021-11-10T21:18:04Z</dc:date>
    </item>
  </channel>
</rss>

