<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why splunkd or splunkweb services do not start after upgrade from Splunk 6.1.1 to 6.2 on Windows 2008 64bit?? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-splunkd-or-splunkweb-services-do-not-start-after-upgrade/m-p/197187#M39177</link>
    <description>&lt;P&gt;Did the required steps, but still no go...&lt;BR /&gt;
R:\Splunk\bin&amp;gt;splunk restart&lt;BR /&gt;
Splunkd: Stopped&lt;/P&gt;

&lt;P&gt;Splunk&amp;gt; The Notorious B.I.G. D.A.T.A.&lt;/P&gt;

&lt;P&gt;Checking prerequisites...&lt;BR /&gt;
        Checking mgmt port [8089]: open&lt;BR /&gt;
        Checking configuration... Error while parsing 'R:\Splunk\etc\modules\int&lt;BR /&gt;
ernal\scheduler\config.xml':&lt;BR /&gt;
 not well-formed (invalid token): line 1, column 0&lt;/P&gt;

&lt;P&gt;There were problems with the configuration files.&lt;BR /&gt;
Would you like to ignore these errors? [y/n]:&lt;/P&gt;

&lt;P&gt;I click Y and tons of errors... (a small clip)&lt;BR /&gt;
        Checking critical directories...        Done&lt;BR /&gt;
[build 237341] 2014-11-10 08:40:31&lt;BR /&gt;
 Access violation, cannot read at address [0x0000000000000010]&lt;BR /&gt;
 Exception address: [0x000000013FB8E213]&lt;BR /&gt;
 Crashing thread: Main Thread&lt;BR /&gt;
    MxCsr:  [0x0000000000001FA0]&lt;BR /&gt;
    SegDs:  [0x000000000000002B]&lt;BR /&gt;
    SegEs:  [0x000000000000002B]&lt;BR /&gt;
    SegFs:  [0x0000000000000053]&lt;BR /&gt;
    SegGs:  [0x000000000000002B]&lt;BR /&gt;
    SegSs:  [0x000000000000002B]&lt;BR /&gt;
    SegCs:  [0x0000000000000033]&lt;BR /&gt;
    EFlags:  [0x0000000000010202]&lt;BR /&gt;
    Rsp:  [0x00000000002DE120]&lt;BR /&gt;
    Rip:  [0x000000013FB8E213] ?&lt;BR /&gt;
    Dr0:  [0x0000000000000000]&lt;BR /&gt;
    Dr1:  [0x0000000000000000]&lt;BR /&gt;
    Dr2:  [0x0000000000000000]&lt;BR /&gt;
    Dr3:  [0x0000000000000000]&lt;BR /&gt;
    Dr6:  [0x0000000000000000]&lt;BR /&gt;
    Dr7:  [0x0000000000000000]&lt;BR /&gt;
    Rax:  [0x0000000000000000]&lt;BR /&gt;
    Rcx:  [0x0000000000000000]&lt;BR /&gt;
    Rdx:  [0x00000000002DE208]&lt;BR /&gt;
    Rbx:  [0x00000001412AE090]&lt;BR /&gt;
    Rbp:  [0x00000000002DEAA0]&lt;BR /&gt;
    Rsi:  [0x0000000000000000]&lt;BR /&gt;
    Rdi:  [0x0000000000000000]&lt;BR /&gt;
    R8:  [0x000007FEF57065A0]&lt;BR /&gt;
    R9:  [0x0000000000000000]&lt;BR /&gt;
    R10:  [0x0000000000000000]&lt;BR /&gt;
    R11:  [0x00000000002DE100]&lt;BR /&gt;
    R12:  [0x0000000000000000]&lt;BR /&gt;
    R13:  [0x0000000000000002]&lt;BR /&gt;
    R14:  [0x00000001412AE090]&lt;BR /&gt;
    R15:  [0x0000000000000000]&lt;BR /&gt;
    DebugControl:  [0x00000000004448D0]&lt;BR /&gt;
    LastBranchToRip:  [0x0000000000000000]&lt;BR /&gt;
    LastBranchFromRip:  [0x0000000000000000]&lt;BR /&gt;
    LastExceptionToRip:  [0x0000000000000000]&lt;BR /&gt;
    LastExceptionFromRip:  [0x0000000000000000]&lt;/P&gt;

&lt;P&gt;OS: Windows&lt;BR /&gt;
 Arch: x86-64&lt;/P&gt;

&lt;P&gt;Backtrace:&lt;BR /&gt;
Splunk ran as local administrator /6.1 Service Pack 1&lt;BR /&gt;
GetLastError(): 0&lt;BR /&gt;
Executable module base: 0x000000013F720000&lt;BR /&gt;
argv: [R:\Splunk\bin\splunkd validatedb]&lt;/P&gt;</description>
    <pubDate>Mon, 10 Nov 2014 13:45:26 GMT</pubDate>
    <dc:creator>mldeschenes</dc:creator>
    <dc:date>2014-11-10T13:45:26Z</dc:date>
    <item>
      <title>Why splunkd or splunkweb services do not start after upgrade from Splunk 6.1.1 to 6.2 on Windows 2008 64bit??</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-splunkd-or-splunkweb-services-do-not-start-after-upgrade/m-p/197185#M39175</link>
      <description>&lt;P&gt;Running windows 2008 64bit , simply wanted to upgrade as it was prompting me too and got annoying so I did now it's busted :).  That's what I get for using free version.&lt;/P&gt;

&lt;P&gt;Windows Event error:&lt;BR /&gt;
Log Name:      Application&lt;BR /&gt;
Source:        Application Error&lt;BR /&gt;
Date:          11/6/2014 2:57:34 PM&lt;BR /&gt;
Event ID:      1000&lt;BR /&gt;
Task Category: (100)&lt;BR /&gt;
Level:         Error&lt;BR /&gt;
Keywords:      Classic&lt;BR /&gt;
User:          N/A&lt;BR /&gt;
Description:&lt;BR /&gt;
Faulting application name: splunkd.exe, version: 1538.0.0.40733, time stamp: 0x5448464d&lt;BR /&gt;
Faulting module name: splunkd.exe, version: 1538.0.0.40733, time stamp: 0x5448464d&lt;BR /&gt;
Exception code: 0xc0000005&lt;BR /&gt;
Fault offset: 0x000000000046e213&lt;BR /&gt;
Faulting process id: 0xcd8&lt;BR /&gt;
Faulting application start time: 0x01cff9fbe8441f46&lt;BR /&gt;
Faulting application path: R:\Splunk\bin\splunkd.exe&lt;BR /&gt;
Faulting module path: R:\Splunk\bin\splunkd.exe&lt;BR /&gt;
Report Id: 2603b6b2-65ef-11e4-a63b-005056983db8&lt;BR /&gt;
Event Xml:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;Provider Name="Application Error" /&amp;gt;
&amp;lt;EventID Qualifiers="0"&amp;gt;1000&amp;lt;/EventID&amp;gt;
&amp;lt;Level&amp;gt;2&amp;lt;/Level&amp;gt;
&amp;lt;Task&amp;gt;100&amp;lt;/Task&amp;gt;
&amp;lt;Keywords&amp;gt;0x80000000000000&amp;lt;/Keywords&amp;gt;
&amp;lt;TimeCreated SystemTime="2014-11-06T19:57:34.000000000Z" /&amp;gt;
&amp;lt;EventRecordID&amp;gt;9372&amp;lt;/EventRecordID&amp;gt;
&amp;lt;Channel&amp;gt;Application&amp;lt;/Channel&amp;gt;
&amp;lt;Security /&amp;gt;


&amp;lt;Data&amp;gt;splunkd.exe&amp;lt;/Data&amp;gt;
&amp;lt;Data&amp;gt;1538.0.0.40733&amp;lt;/Data&amp;gt;
&amp;lt;Data&amp;gt;5448464d&amp;lt;/Data&amp;gt;
&amp;lt;Data&amp;gt;splunkd.exe&amp;lt;/Data&amp;gt;
&amp;lt;Data&amp;gt;1538.0.0.40733&amp;lt;/Data&amp;gt;
&amp;lt;Data&amp;gt;5448464d&amp;lt;/Data&amp;gt;
&amp;lt;Data&amp;gt;c0000005&amp;lt;/Data&amp;gt;
&amp;lt;Data&amp;gt;000000000046e213&amp;lt;/Data&amp;gt;
&amp;lt;Data&amp;gt;cd8&amp;lt;/Data&amp;gt;
&amp;lt;Data&amp;gt;01cff9fbe8441f46&amp;lt;/Data&amp;gt;
&amp;lt;Data&amp;gt;R:\Splunk\bin\splunkd.exe&amp;lt;/Data&amp;gt;
&amp;lt;Data&amp;gt;R:\Splunk\bin\splunkd.exe&amp;lt;/Data&amp;gt;
&amp;lt;Data&amp;gt;2603b6b2-65ef-11e4-a63b-005056983db8&amp;lt;/Data&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 06 Nov 2014 20:05:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-splunkd-or-splunkweb-services-do-not-start-after-upgrade/m-p/197185#M39175</guid>
      <dc:creator>mldeschenes</dc:creator>
      <dc:date>2014-11-06T20:05:58Z</dc:date>
    </item>
    <item>
      <title>Re: Why splunkd or splunkweb services do not start after upgrade from Splunk 6.1.1 to 6.2 on Windows 2008 64bit??</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-splunkd-or-splunkweb-services-do-not-start-after-upgrade/m-p/197186#M39176</link>
      <description>&lt;P&gt;The very first thing i would do is re-apply default security. &lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;At the top level folder  right click and properties. &lt;/LI&gt;
&lt;LI&gt;Select Security Tab&lt;/LI&gt;
&lt;LI&gt;Click Advanced&lt;/LI&gt;
&lt;LI&gt;Change Permissions&lt;/LI&gt;
&lt;LI&gt;Select both check boxes at bottom&lt;/LI&gt;
&lt;LI&gt;Click OK&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Now open a dos prompt and issues a Splunk Restart from R:\Splunk\bin&lt;/P&gt;

&lt;P&gt;Important note: Use dos to restart the splunk processes as it will display errors or other warnings you might have missed by using service manager. &lt;/P&gt;</description>
      <pubDate>Thu, 06 Nov 2014 21:16:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-splunkd-or-splunkweb-services-do-not-start-after-upgrade/m-p/197186#M39176</guid>
      <dc:creator>MartinMcNutt</dc:creator>
      <dc:date>2014-11-06T21:16:34Z</dc:date>
    </item>
    <item>
      <title>Re: Why splunkd or splunkweb services do not start after upgrade from Splunk 6.1.1 to 6.2 on Windows 2008 64bit??</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-splunkd-or-splunkweb-services-do-not-start-after-upgrade/m-p/197187#M39177</link>
      <description>&lt;P&gt;Did the required steps, but still no go...&lt;BR /&gt;
R:\Splunk\bin&amp;gt;splunk restart&lt;BR /&gt;
Splunkd: Stopped&lt;/P&gt;

&lt;P&gt;Splunk&amp;gt; The Notorious B.I.G. D.A.T.A.&lt;/P&gt;

&lt;P&gt;Checking prerequisites...&lt;BR /&gt;
        Checking mgmt port [8089]: open&lt;BR /&gt;
        Checking configuration... Error while parsing 'R:\Splunk\etc\modules\int&lt;BR /&gt;
ernal\scheduler\config.xml':&lt;BR /&gt;
 not well-formed (invalid token): line 1, column 0&lt;/P&gt;

&lt;P&gt;There were problems with the configuration files.&lt;BR /&gt;
Would you like to ignore these errors? [y/n]:&lt;/P&gt;

&lt;P&gt;I click Y and tons of errors... (a small clip)&lt;BR /&gt;
        Checking critical directories...        Done&lt;BR /&gt;
[build 237341] 2014-11-10 08:40:31&lt;BR /&gt;
 Access violation, cannot read at address [0x0000000000000010]&lt;BR /&gt;
 Exception address: [0x000000013FB8E213]&lt;BR /&gt;
 Crashing thread: Main Thread&lt;BR /&gt;
    MxCsr:  [0x0000000000001FA0]&lt;BR /&gt;
    SegDs:  [0x000000000000002B]&lt;BR /&gt;
    SegEs:  [0x000000000000002B]&lt;BR /&gt;
    SegFs:  [0x0000000000000053]&lt;BR /&gt;
    SegGs:  [0x000000000000002B]&lt;BR /&gt;
    SegSs:  [0x000000000000002B]&lt;BR /&gt;
    SegCs:  [0x0000000000000033]&lt;BR /&gt;
    EFlags:  [0x0000000000010202]&lt;BR /&gt;
    Rsp:  [0x00000000002DE120]&lt;BR /&gt;
    Rip:  [0x000000013FB8E213] ?&lt;BR /&gt;
    Dr0:  [0x0000000000000000]&lt;BR /&gt;
    Dr1:  [0x0000000000000000]&lt;BR /&gt;
    Dr2:  [0x0000000000000000]&lt;BR /&gt;
    Dr3:  [0x0000000000000000]&lt;BR /&gt;
    Dr6:  [0x0000000000000000]&lt;BR /&gt;
    Dr7:  [0x0000000000000000]&lt;BR /&gt;
    Rax:  [0x0000000000000000]&lt;BR /&gt;
    Rcx:  [0x0000000000000000]&lt;BR /&gt;
    Rdx:  [0x00000000002DE208]&lt;BR /&gt;
    Rbx:  [0x00000001412AE090]&lt;BR /&gt;
    Rbp:  [0x00000000002DEAA0]&lt;BR /&gt;
    Rsi:  [0x0000000000000000]&lt;BR /&gt;
    Rdi:  [0x0000000000000000]&lt;BR /&gt;
    R8:  [0x000007FEF57065A0]&lt;BR /&gt;
    R9:  [0x0000000000000000]&lt;BR /&gt;
    R10:  [0x0000000000000000]&lt;BR /&gt;
    R11:  [0x00000000002DE100]&lt;BR /&gt;
    R12:  [0x0000000000000000]&lt;BR /&gt;
    R13:  [0x0000000000000002]&lt;BR /&gt;
    R14:  [0x00000001412AE090]&lt;BR /&gt;
    R15:  [0x0000000000000000]&lt;BR /&gt;
    DebugControl:  [0x00000000004448D0]&lt;BR /&gt;
    LastBranchToRip:  [0x0000000000000000]&lt;BR /&gt;
    LastBranchFromRip:  [0x0000000000000000]&lt;BR /&gt;
    LastExceptionToRip:  [0x0000000000000000]&lt;BR /&gt;
    LastExceptionFromRip:  [0x0000000000000000]&lt;/P&gt;

&lt;P&gt;OS: Windows&lt;BR /&gt;
 Arch: x86-64&lt;/P&gt;

&lt;P&gt;Backtrace:&lt;BR /&gt;
Splunk ran as local administrator /6.1 Service Pack 1&lt;BR /&gt;
GetLastError(): 0&lt;BR /&gt;
Executable module base: 0x000000013F720000&lt;BR /&gt;
argv: [R:\Splunk\bin\splunkd validatedb]&lt;/P&gt;</description>
      <pubDate>Mon, 10 Nov 2014 13:45:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-splunkd-or-splunkweb-services-do-not-start-after-upgrade/m-p/197187#M39177</guid>
      <dc:creator>mldeschenes</dc:creator>
      <dc:date>2014-11-10T13:45:26Z</dc:date>
    </item>
    <item>
      <title>Re: Why splunkd or splunkweb services do not start after upgrade from Splunk 6.1.1 to 6.2 on Windows 2008 64bit??</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-splunkd-or-splunkweb-services-do-not-start-after-upgrade/m-p/197188#M39178</link>
      <description>&lt;P&gt;I validated that config.xml file and all I see in the file is 1 line&lt;BR /&gt;
null null null null.....&lt;/P&gt;</description>
      <pubDate>Mon, 10 Nov 2014 15:23:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-splunkd-or-splunkweb-services-do-not-start-after-upgrade/m-p/197188#M39178</guid>
      <dc:creator>mldeschenes</dc:creator>
      <dc:date>2014-11-10T15:23:42Z</dc:date>
    </item>
    <item>
      <title>Re: Why splunkd or splunkweb services do not start after upgrade from Splunk 6.1.1 to 6.2 on Windows 2008 64bit??</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-splunkd-or-splunkweb-services-do-not-start-after-upgrade/m-p/197189#M39179</link>
      <description>&lt;P&gt;Managed to upgrade to 6.2.x... for some reason I had to use local systems account during install process did not like using domain account we had assigned.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Nov 2014 16:26:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-splunkd-or-splunkweb-services-do-not-start-after-upgrade/m-p/197189#M39179</guid>
      <dc:creator>mldeschenes</dc:creator>
      <dc:date>2014-11-12T16:26:19Z</dc:date>
    </item>
  </channel>
</rss>

