<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk-optimize Warning ... in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-optimize-Warning/m-p/11077#M504</link>
    <description>&lt;P&gt;The splunk-optimize process can´t run on that subdirectory, since it doesn´t exist.
Even if i create it manually, splunk-optimize won´t notice, except by creating another error:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;05-11-2010 13:10:40.476 ERROR databasePartitionPolicy - Index is empty refusing to move. oldDirPath=/opt/splunk/splunk/var/lib/splunk/fishbucket/db/db-hot
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The other message is still there:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;05-11-2010 14:33:52.045 WARN  timeinvertedIndex - splunk-optimize failed to start for index /opt/splunk/var/lib/splunk/fishbucket/db/db-hot
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Tue, 11 May 2010 19:40:08 GMT</pubDate>
    <dc:creator>tpaulsen</dc:creator>
    <dc:date>2010-05-11T19:40:08Z</dc:date>
    <item>
      <title>Splunk-optimize Warning ...</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-optimize-Warning/m-p/11073#M500</link>
      <description>&lt;P&gt;Can't find a reference to the following error. What does it mean and how do I fix it?&lt;/P&gt;

&lt;P&gt;Indexing Significant Warns:&lt;/P&gt;

&lt;P&gt;WARN  timeinvertedIndex - splunk-optimize failed to start for index /opt/splunk/var/lib/splunk/defaultdb/db/hot_quar_v1_17&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2010 19:47:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-optimize-Warning/m-p/11073#M500</guid>
      <dc:creator>MikeyG</dc:creator>
      <dc:date>2010-04-07T19:47:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk-optimize Warning ...</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-optimize-Warning/m-p/11074#M501</link>
      <description>&lt;P&gt;Sporadic failures are to be expected, as there are times when Splunk will be indexing heavily to a particular hot DB, and it won't always be the optimal time for splunk-optimize to run on that particular bucket.&lt;/P&gt;

&lt;P&gt;If it's a consistent failure however, and splunk-optimize has never been able to run on that bucket, that may indicate a more serious problem with the data inside the bucket - a possible data corruption for example.&lt;/P&gt;

&lt;P&gt;If it's a consistent message, you should file a case with the Splunk Support team and they will work with you to determine the root cause - &lt;A href="http://www.splunk.com/page/submit_issue" rel="nofollow"&gt;http://www.splunk.com/page/submit_issue&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2010 19:47:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-optimize-Warning/m-p/11074#M501</guid>
      <dc:creator>Mick</dc:creator>
      <dc:date>2010-04-07T19:47:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk-optimize Warning ...</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-optimize-Warning/m-p/11075#M502</link>
      <description>&lt;P&gt;If it's expected, why is it a failure?&lt;BR /&gt;
What does it mean that it isn't an optimal time, is this a locking issue?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2010 19:47:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-optimize-Warning/m-p/11075#M502</guid>
      <dc:creator>jrodman</dc:creator>
      <dc:date>2010-04-07T19:47:46Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk-optimize Warning ...</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-optimize-Warning/m-p/11076#M503</link>
      <description>&lt;P&gt;There is nothing to fix if it's rare. It just means that Splunk was busy at the time it would otherwise have run an optimization on the indexed data. Optimization runs frequently to improve the way data is stored in the index as new data gets added.&lt;/P&gt;

&lt;P&gt;If the warning occurs regularly, it is a sign that your system is overloaded. If the warning occurs more often than every few minutes, your indexed data may not be well optimized which will lead to slower searches over that data.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2010 21:33:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-optimize-Warning/m-p/11076#M503</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-04-07T21:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk-optimize Warning ...</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-optimize-Warning/m-p/11077#M504</link>
      <description>&lt;P&gt;The splunk-optimize process can´t run on that subdirectory, since it doesn´t exist.
Even if i create it manually, splunk-optimize won´t notice, except by creating another error:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;05-11-2010 13:10:40.476 ERROR databasePartitionPolicy - Index is empty refusing to move. oldDirPath=/opt/splunk/splunk/var/lib/splunk/fishbucket/db/db-hot
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The other message is still there:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;05-11-2010 14:33:52.045 WARN  timeinvertedIndex - splunk-optimize failed to start for index /opt/splunk/var/lib/splunk/fishbucket/db/db-hot
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 11 May 2010 19:40:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-optimize-Warning/m-p/11077#M504</guid>
      <dc:creator>tpaulsen</dc:creator>
      <dc:date>2010-05-11T19:40:08Z</dc:date>
    </item>
  </channel>
</rss>

