<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why am I getting Access is denied errors on indexers? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-getting-Access-is-denied-errors-on-indexers/m-p/483490#M82836</link>
    <description>&lt;P&gt;I have cluster with 2 indexers, RF=2 running Splunk version 7.1.2 on Windows Server 2012.&lt;BR /&gt;
I often get following error:&lt;BR /&gt;
Indexer Clustering: too many bucket replication errors to target peer.&lt;/P&gt;

&lt;P&gt;In splunkd.log on both indexers I found similar errors:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;ERROR TimeInvertedIndex - Failed to rename from="C:\Splunk\var\lib\splunk\audit\db\hot_v1_278\.rawSize_tmp" to="C:\Splunk\var\lib\splunk\audit\db\hot_v1_278\.rawSize": Access is denied.

ERROR LMApplyResponse - failed to rename C:\Splunk\var\lib\splunk\fishbucket\rawdata\1322324208-C:\Splunk\var\lib\splunk\fishbucket\rawdata\1322324208.old [1,1,1] (Access is denied.)

ERROR HotBucketRoller - Unable to rename from='C:\Splunk\var\lib\splunk\_internaldb\db\hot_v1_572' to='C:\Splunk\var\lib\splunk\_internaldb\db\db_1570774736_1570503894_572_F0C749EE-B861-4598-B107-5358365E79D8' because The system cannot find the file specified.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;and so on.&lt;BR /&gt;
AND NO BUCKETS IN FIXUP STATE.&lt;/P&gt;

&lt;P&gt;Splunk is installed under local OS Admin (no AD).&lt;BR /&gt;
I checked file permissions for fishbucket\rawdata*.old files and found that no user or group has any access to it, even SYSTEM!&lt;/P&gt;

&lt;P&gt;My steps:&lt;BR /&gt;
1. Removed fishbucket\rawdata\1322324208.old file&lt;BR /&gt;
2. Executed icacls.exe commands in order to fix Splunk directory permissions:&lt;BR /&gt;
icacls.exe "C:\Splunk" /inheritance:e /T&lt;BR /&gt;
icacls.exe "C:\Splunk" /T /Q /reset&lt;BR /&gt;
3. Initiated rolling restart on Master Node. Indexers entered maintenance mode and restarted. &lt;BR /&gt;
This caused a huge number of fixup tasks after restarts succeeded and fixed all issues for some time, but today I got same issues with other buckets.&lt;/P&gt;

&lt;P&gt;Why Splunk still creates files with bad access rights? What I can do in this situation? Maybe reinstall Splunk?&lt;/P&gt;

&lt;P&gt;Note: I know that running Splunk on Windows is pain and I can't move to Linux servers. I have 2 other clusters with indexers running on Windows and they do well.&lt;/P&gt;</description>
    <pubDate>Thu, 14 Nov 2019 16:38:33 GMT</pubDate>
    <dc:creator>asnegina</dc:creator>
    <dc:date>2019-11-14T16:38:33Z</dc:date>
    <item>
      <title>Why am I getting Access is denied errors on indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-getting-Access-is-denied-errors-on-indexers/m-p/483490#M82836</link>
      <description>&lt;P&gt;I have cluster with 2 indexers, RF=2 running Splunk version 7.1.2 on Windows Server 2012.&lt;BR /&gt;
I often get following error:&lt;BR /&gt;
Indexer Clustering: too many bucket replication errors to target peer.&lt;/P&gt;

&lt;P&gt;In splunkd.log on both indexers I found similar errors:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;ERROR TimeInvertedIndex - Failed to rename from="C:\Splunk\var\lib\splunk\audit\db\hot_v1_278\.rawSize_tmp" to="C:\Splunk\var\lib\splunk\audit\db\hot_v1_278\.rawSize": Access is denied.

ERROR LMApplyResponse - failed to rename C:\Splunk\var\lib\splunk\fishbucket\rawdata\1322324208-C:\Splunk\var\lib\splunk\fishbucket\rawdata\1322324208.old [1,1,1] (Access is denied.)

ERROR HotBucketRoller - Unable to rename from='C:\Splunk\var\lib\splunk\_internaldb\db\hot_v1_572' to='C:\Splunk\var\lib\splunk\_internaldb\db\db_1570774736_1570503894_572_F0C749EE-B861-4598-B107-5358365E79D8' because The system cannot find the file specified.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;and so on.&lt;BR /&gt;
AND NO BUCKETS IN FIXUP STATE.&lt;/P&gt;

&lt;P&gt;Splunk is installed under local OS Admin (no AD).&lt;BR /&gt;
I checked file permissions for fishbucket\rawdata*.old files and found that no user or group has any access to it, even SYSTEM!&lt;/P&gt;

&lt;P&gt;My steps:&lt;BR /&gt;
1. Removed fishbucket\rawdata\1322324208.old file&lt;BR /&gt;
2. Executed icacls.exe commands in order to fix Splunk directory permissions:&lt;BR /&gt;
icacls.exe "C:\Splunk" /inheritance:e /T&lt;BR /&gt;
icacls.exe "C:\Splunk" /T /Q /reset&lt;BR /&gt;
3. Initiated rolling restart on Master Node. Indexers entered maintenance mode and restarted. &lt;BR /&gt;
This caused a huge number of fixup tasks after restarts succeeded and fixed all issues for some time, but today I got same issues with other buckets.&lt;/P&gt;

&lt;P&gt;Why Splunk still creates files with bad access rights? What I can do in this situation? Maybe reinstall Splunk?&lt;/P&gt;

&lt;P&gt;Note: I know that running Splunk on Windows is pain and I can't move to Linux servers. I have 2 other clusters with indexers running on Windows and they do well.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2019 16:38:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-getting-Access-is-denied-errors-on-indexers/m-p/483490#M82836</guid>
      <dc:creator>asnegina</dc:creator>
      <dc:date>2019-11-14T16:38:33Z</dc:date>
    </item>
  </channel>
</rss>

