<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Indexer fails on startup in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-fails-on-startup/m-p/450047#M78140</link>
    <description>&lt;P&gt;When I try and restart one of my indexers after an OS upgrade I am seeing the following messages. My 2 other indexers are up and running. How do I fix this. I found one articale where they talk about fixing the offending buckets but don't say how and I am not positive this is the same issue&lt;/P&gt;

&lt;P&gt;09-06-2018 06:37:17.576 -0400 ERROR DatabaseDirectoryManager - idx=main bid=main~392~F18EA0F4-48F1-4D8C-8209-5B40F&lt;BR /&gt;
0B66E1E bucket=392_F18EA0F4-48F1-4D8C-8209-5B40F0B66E1E Detected directory manually copied into its database, caus&lt;BR /&gt;
ing id conflicts [path1='/opt/splunk/var/lib/splunk/defaultdb/db/rb_1535649215_1535592644_392_F18EA0F4-48F1-4D8C-8&lt;BR /&gt;
209-5B40F0B66E1E' path2='/opt/splunk/var/lib/splunk/defaultdb/db/392_F18EA0F4-48F1-4D8C-8209-5B40F0B66E1E'].&lt;BR /&gt;
09-06-2018 06:37:17.579 -0400 ERROR IndexerService - Error intializing IndexerService: idx=main bid=main~392~F18EA&lt;BR /&gt;
0F4-48F1-4D8C-8209-5B40F0B66E1E bucket=392_F18EA0F4-48F1-4D8C-8209-5B40F0B66E1E Detected directory manually copied&lt;BR /&gt;
 into its database, causing id conflicts [path1='/opt/splunk/var/lib/splunk/defaultdb/db/rb_1535649215_1535592644_&lt;BR /&gt;
392_F18EA0F4-48F1-4D8C-8209-5B40F0B66E1E' path2='/opt/splunk/var/lib/splunk/defaultdb/db/392_F18EA0F4-48F1-4D8C-82&lt;BR /&gt;
09-5B40F0B66E1E'].&lt;/P&gt;

&lt;P&gt;09-06-2018 06:37:17.584 -0400 FATAL IndexerService - One or more indexes could not be initialized.  Cannot disable&lt;BR /&gt;
 indexes on a clustering slave.&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 21:11:55 GMT</pubDate>
    <dc:creator>a238574</dc:creator>
    <dc:date>2020-09-29T21:11:55Z</dc:date>
    <item>
      <title>Indexer fails on startup</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-fails-on-startup/m-p/450047#M78140</link>
      <description>&lt;P&gt;When I try and restart one of my indexers after an OS upgrade I am seeing the following messages. My 2 other indexers are up and running. How do I fix this. I found one articale where they talk about fixing the offending buckets but don't say how and I am not positive this is the same issue&lt;/P&gt;

&lt;P&gt;09-06-2018 06:37:17.576 -0400 ERROR DatabaseDirectoryManager - idx=main bid=main~392~F18EA0F4-48F1-4D8C-8209-5B40F&lt;BR /&gt;
0B66E1E bucket=392_F18EA0F4-48F1-4D8C-8209-5B40F0B66E1E Detected directory manually copied into its database, caus&lt;BR /&gt;
ing id conflicts [path1='/opt/splunk/var/lib/splunk/defaultdb/db/rb_1535649215_1535592644_392_F18EA0F4-48F1-4D8C-8&lt;BR /&gt;
209-5B40F0B66E1E' path2='/opt/splunk/var/lib/splunk/defaultdb/db/392_F18EA0F4-48F1-4D8C-8209-5B40F0B66E1E'].&lt;BR /&gt;
09-06-2018 06:37:17.579 -0400 ERROR IndexerService - Error intializing IndexerService: idx=main bid=main~392~F18EA&lt;BR /&gt;
0F4-48F1-4D8C-8209-5B40F0B66E1E bucket=392_F18EA0F4-48F1-4D8C-8209-5B40F0B66E1E Detected directory manually copied&lt;BR /&gt;
 into its database, causing id conflicts [path1='/opt/splunk/var/lib/splunk/defaultdb/db/rb_1535649215_1535592644_&lt;BR /&gt;
392_F18EA0F4-48F1-4D8C-8209-5B40F0B66E1E' path2='/opt/splunk/var/lib/splunk/defaultdb/db/392_F18EA0F4-48F1-4D8C-82&lt;BR /&gt;
09-5B40F0B66E1E'].&lt;/P&gt;

&lt;P&gt;09-06-2018 06:37:17.584 -0400 FATAL IndexerService - One or more indexes could not be initialized.  Cannot disable&lt;BR /&gt;
 indexes on a clustering slave.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 21:11:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-fails-on-startup/m-p/450047#M78140</guid>
      <dc:creator>a238574</dc:creator>
      <dc:date>2020-09-29T21:11:55Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer fails on startup</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-fails-on-startup/m-p/450048#M78141</link>
      <description>&lt;P&gt;Hi @a238574,&lt;/P&gt;

&lt;P&gt;Based on logs there is Bucket ID conflict in your &lt;CODE&gt;main&lt;/CODE&gt; index.&lt;/P&gt;

&lt;P&gt;You have Bucket ID &lt;CODE&gt;392&lt;/CODE&gt; at &lt;CODE&gt;/opt/splunk/var/lib/splunk/defaultdb/db/rb_1535649215_1535592644_392_F18EA0F4-48F1-4D8C-8209-5B40F0B66E1E&lt;/CODE&gt; and &lt;CODE&gt;/opt/splunk/var/lib/splunk/defaultdb/db/392_F18EA0F4-48F1-4D8C-8209-5B40F0B66E1E&lt;/CODE&gt; in same index which is causing issue here. The thing is bucket starting with &lt;CODE&gt;rb_&lt;/CODE&gt; is a replicated bucket and should replicated from different indexer but here it looks like you have same &lt;CODE&gt;GUID - F18EA0F4-48F1-4D8C-8209-5B40F0B66E1E&lt;/CODE&gt; across different indexers. Each Indexer should have different &lt;CODE&gt;GUID&lt;/CODE&gt; so first check across your indexer with duplicated GUID. &lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 11:51:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-fails-on-startup/m-p/450048#M78141</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2018-09-06T11:51:40Z</dc:date>
    </item>
  </channel>
</rss>

