<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Indexer Splunkd services are not able to run in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-Splunkd-services-are-not-able-to-run/m-p/498663#M84984</link>
    <description>&lt;P&gt;Have you checked splunkd.log?&lt;/P&gt;</description>
    <pubDate>Thu, 14 May 2020 12:18:53 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2020-05-14T12:18:53Z</dc:date>
    <item>
      <title>Indexer Splunkd services are not able to run</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-Splunkd-services-are-not-able-to-run/m-p/498660#M84981</link>
      <description>&lt;P&gt;In indexer cluster environment one of the Indexer got stopped unable to start/restart&lt;BR /&gt;
&lt;STRONG&gt;C:\Windows\system32&amp;gt;d:&lt;BR /&gt;
D:&amp;gt;cd spluk\bin&lt;BR /&gt;
The system cannot find the path specified.&lt;BR /&gt;
D:&amp;gt;cd splunk\bin&lt;BR /&gt;
D:\Splunk\bin&amp;gt;.\splunk restart&lt;BR /&gt;
Splunkd: Stopped&lt;BR /&gt;
Splunk&amp;gt; All batbelt. No tights.&lt;BR /&gt;
Checking prerequisites...&lt;BR /&gt;
        Checking http port [8000]: open&lt;BR /&gt;
        Checking mgmt port [8089]: open&lt;BR /&gt;
        Checking appserver port [127.0.0.1:8065]: open&lt;BR /&gt;
        Checking kvstore port [8191]: open&lt;BR /&gt;
        Checking configuration...  Done.&lt;BR /&gt;
        Checking critical directories...        Done&lt;BR /&gt;
        Checking indexes...&lt;BR /&gt;
                (skipping validation of index paths because not running as&lt;BR /&gt;
LocalSystem)&lt;BR /&gt;
                Validated: _audit _internal _introspection _telemetry _thef&lt;BR /&gt;
ishbucket aws_anomaly_detection aws_topology_daily_snapshot aws_topology_hi&lt;BR /&gt;
story aws_topology_monthly_snapshot aws_topology_playback aws_vpc_flow_logs&lt;BR /&gt;
 history main summary&lt;BR /&gt;
        Done&lt;BR /&gt;
Bypassing local license checks since this instance is configured with a rem&lt;BR /&gt;
ote license master.&lt;BR /&gt;
        Checking filesystem compatibility...  Done&lt;BR /&gt;
        Checking conf files for problems...&lt;BR /&gt;
        Done&lt;BR /&gt;
        Checking default conf files for edits...&lt;BR /&gt;
        Validating installed files against hashes from 'D:\Splunk\splunk-7.&lt;BR /&gt;
2.1-be11b2c46e23-windows-64-manifest'&lt;BR /&gt;
        All installed files intact.&lt;BR /&gt;
        Done&lt;BR /&gt;
        Checking replication_port port [7778]: open&lt;BR /&gt;
All preliminary checks passed.&lt;BR /&gt;
Starting splunk server daemon (splunkd)...&lt;BR /&gt;
Splunkd: Starting (pid 6420)&lt;BR /&gt;
Timed out waiting for splunkd to start.&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Splunkd.log&lt;BR /&gt;
05-18-2020 07:31:58.157 +0000 INFO ServerRoles - Declared role=cluster_slave.&lt;BR /&gt;
05-18-2020 07:31:58.157 +0000 INFO ServerRoles - Declared role=indexer.&lt;BR /&gt;
05-18-2020 07:31:58.157 +0000 INFO ClusteringMgr - initing clustering with: ht=60.000 rf=3 sf=2 ct=60.000 st=60.000 rt=60.000 rct=60.000 rst=60.000 rrt=60.000 rmst=180.000 rmrt=180.000 icps=-1 sfrt=600.000 pe=1 im=0 is=1 mob=5 mor=5 mosr=5 pb=5 rep_port=port=7778 isSsl=0 ipv6=0 cipherSuite= ecdhCurveNames= sslVersions=SSL3,TLS1.0,TLS1.1,TLS1.2 compressed=1 allowSslRenegotiation=1 dhFile= reqCliCert=0 serverCert= rootCA= commonNames= alternateNames= pptr=10 fznb=10 Empty/Default cluster pass4symmkey=true allow Empty/Default cluster pass4symmkey=true rrt=restart dft=180 abt=600 sbs=1&lt;BR /&gt;
05-18-2020 07:31:58.172 +0000 INFO ClusteringMgr - Initializing node as slave&lt;BR /&gt;
05-18-2020 07:31:58.172 +0000 INFO BucketReplicator - Initializing BucketReplicatorMgr&lt;BR /&gt;
05-18-2020 07:31:58.219 +0000 INFO CMServiceThread - CMHealthManager starting eloop&lt;BR /&gt;
05-18-2020 07:31:58.235 +0000 INFO CMBundleMgr - bundle=D:\Splunk\var\run\splunk\cluster\remote-bundle\2df598296706d9846433003de4c7a927-1589221919.bundle, checksum=5F5C9F53A58CD618B69209EBC5D92286 found on the slave&lt;BR /&gt;
05-18-2020 07:31:58.235 +0000 INFO CMBundleMgr - setting active bundle= to latest bundle=6F0874F9DA123EA345D25A77F6D3CAFA&lt;BR /&gt;
05-18-2020 07:31:58.235 +0000 INFO CMSlave - event=getActiveBundle status=success path=D:\Splunk\var\run\splunk\cluster\remote-bundle\83209f7543173582062b08f2b77fcde0-1589259155.bundle cksum=6F0874F9DA123EA345D25A77F6D3CAFA alreadyin=0&lt;BR /&gt;
05-18-2020 07:31:58.235 +0000 ERROR CMSlave - event=move downloaded bundle to slave-apps failed with err="failed to remove dir=D:\Splunk\etc\slave-apps.old (There are no more files.)" even after multiple attempts, Exiting..&lt;BR /&gt;
05-18-2020 07:31:58.235 +0000 ERROR loader - Failed to download bundle from master, err="failed to remove dir=D:\Splunk\etc\slave-apps.old (There are no more files.)", Won't start splunkd.&lt;/P&gt;

&lt;P&gt;please provide the solution if any one knows.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 05:26:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-Splunkd-services-are-not-able-to-run/m-p/498660#M84981</guid>
      <dc:creator>phanichintha</dc:creator>
      <dc:date>2020-09-30T05:26:08Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer Splunkd services are not able to run</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-Splunkd-services-are-not-able-to-run/m-p/498661#M84982</link>
      <description>&lt;P&gt;Have you checked splunkd.log on the indexer?&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2020 14:29:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-Splunkd-services-are-not-able-to-run/m-p/498661#M84982</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-05-13T14:29:02Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer Splunkd services are not able to run</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-Splunkd-services-are-not-able-to-run/m-p/498662#M84983</link>
      <description>&lt;P&gt;05-14-2020 05:12:43.575 +0000 INFO  ServerRoles - Declared role=cluster_slave.&lt;BR /&gt;
05-14-2020 05:12:43.575 +0000 INFO  ServerRoles - Declared role=indexer.&lt;BR /&gt;
05-14-2020 05:12:43.575 +0000 INFO  ClusteringMgr - initing clustering with: ht=60.000 rf=3 sf=2 ct=60.000 st=60.000 rt=60.000 rct=60.000 rst=60.000 rrt=60.000 rmst=180.000 rmrt=180.000 icps=-1 sfrt=600.000 pe=1 im=0 is=1 mob=5 mor=5 mosr=5 pb=5 rep_port=port=7778 isSsl=0 ipv6=0 cipherSuite= ecdhCurveNames= sslVersions=SSL3,TLS1.0,TLS1.1,TLS1.2 compressed=1 allowSslRenegotiation=1 dhFile= reqCliCert=0 serverCert= rootCA= commonNames= alternateNames= pptr=10 fznb=10 Empty/Default cluster pass4symmkey=true allow Empty/Default cluster pass4symmkey=true rrt=restart dft=180 abt=600 sbs=1&lt;BR /&gt;
05-14-2020 05:12:43.575 +0000 INFO  ClusteringMgr - Initializing node as slave&lt;BR /&gt;
05-14-2020 05:12:43.575 +0000 INFO  BucketReplicator - Initializing BucketReplicatorMgr&lt;BR /&gt;
05-14-2020 05:12:43.638 +0000 INFO  CMServiceThread - CMHealthManager starting eloop&lt;BR /&gt;
05-14-2020 05:12:43.638 +0000 INFO  CMBundleMgr - bundle=D:\Splunk\var\run\splunk\cluster\remote-bundle\2df598296706d9846433003de4c7a927-1589221919.bundle, checksum=5F5C9F53A58CD618B69209EBC5D92286 found on the slave&lt;BR /&gt;
05-14-2020 05:12:43.638 +0000 INFO  CMBundleMgr - setting active bundle= to latest bundle=6F0874F9DA123EA345D25A77F6D3CAFA&lt;BR /&gt;
05-14-2020 05:12:43.638 +0000 INFO  CMSlave - event=getActiveBundle status=success path=D:\Splunk\var\run\splunk\cluster\remote-bundle\83209f7543173582062b08f2b77fcde0-1589259155.bundle cksum=6F0874F9DA123EA345D25A77F6D3CAFA alreadyin=0&lt;BR /&gt;
05-14-2020 05:12:43.638 +0000 ERROR CMSlave - event=move downloaded bundle to slave-apps failed with err="failed to remove dir=D:\Splunk\etc\slave-apps.old (There are no more files.)" even after multiple attempts, Exiting..&lt;BR /&gt;
05-14-2020 05:12:43.638 +0000 ERROR loader - Failed to download bundle from master, err="failed to remove dir=D:\Splunk\etc\slave-apps.old (There are no more files.)", Won't start splunkd.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 05:26:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-Splunkd-services-are-not-able-to-run/m-p/498662#M84983</guid>
      <dc:creator>phanichintha</dc:creator>
      <dc:date>2020-09-30T05:26:25Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer Splunkd services are not able to run</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-Splunkd-services-are-not-able-to-run/m-p/498663#M84984</link>
      <description>&lt;P&gt;Have you checked splunkd.log?&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2020 12:18:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-Splunkd-services-are-not-able-to-run/m-p/498663#M84984</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-05-14T12:18:53Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer Splunkd services are not able to run</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-Splunkd-services-are-not-able-to-run/m-p/498664#M84985</link>
      <description>&lt;P&gt;Hello @phanichintha,&lt;/P&gt;

&lt;P&gt;as there are no splunkd.log provided as asked by @richgalloway , you'd be better to open a support ticket&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2020 08:01:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-Splunkd-services-are-not-able-to-run/m-p/498664#M84985</guid>
      <dc:creator>PavelP</dc:creator>
      <dc:date>2020-05-18T08:01:37Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer Splunkd services are not able to run</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-Splunkd-services-are-not-able-to-run/m-p/498665#M84986</link>
      <description>&lt;P&gt;Hello guys, pl check this &lt;BR /&gt;
Splunkd.log&lt;BR /&gt;
05-18-2020 07:31:58.157 +0000 INFO ServerRoles - Declared role=cluster_slave.&lt;BR /&gt;
05-18-2020 07:31:58.157 +0000 INFO ServerRoles - Declared role=indexer.&lt;BR /&gt;
05-18-2020 07:31:58.157 +0000 INFO ClusteringMgr - initing clustering with: ht=60.000 rf=3 sf=2 ct=60.000 st=60.000 rt=60.000 rct=60.000 rst=60.000 rrt=60.000 rmst=180.000 rmrt=180.000 icps=-1 sfrt=600.000 pe=1 im=0 is=1 mob=5 mor=5 mosr=5 pb=5 rep_port=port=7778 isSsl=0 ipv6=0 cipherSuite= ecdhCurveNames= sslVersions=SSL3,TLS1.0,TLS1.1,TLS1.2 compressed=1 allowSslRenegotiation=1 dhFile= reqCliCert=0 serverCert= rootCA= commonNames= alternateNames= pptr=10 fznb=10 Empty/Default cluster pass4symmkey=true allow Empty/Default cluster pass4symmkey=true rrt=restart dft=180 abt=600 sbs=1&lt;BR /&gt;
05-18-2020 07:31:58.172 +0000 INFO ClusteringMgr - Initializing node as slave&lt;BR /&gt;
05-18-2020 07:31:58.172 +0000 INFO BucketReplicator - Initializing BucketReplicatorMgr&lt;BR /&gt;
05-18-2020 07:31:58.219 +0000 INFO CMServiceThread - CMHealthManager starting eloop&lt;BR /&gt;
05-18-2020 07:31:58.235 +0000 INFO CMBundleMgr - bundle=D:\Splunk\var\run\splunk\cluster\remote-bundle\2df598296706d9846433003de4c7a927-1589221919.bundle, checksum=5F5C9F53A58CD618B69209EBC5D92286 found on the slave&lt;BR /&gt;
05-18-2020 07:31:58.235 +0000 INFO CMBundleMgr - setting active bundle= to latest bundle=6F0874F9DA123EA345D25A77F6D3CAFA&lt;BR /&gt;
05-18-2020 07:31:58.235 +0000 INFO CMSlave - event=getActiveBundle status=success path=D:\Splunk\var\run\splunk\cluster\remote-bundle\83209f7543173582062b08f2b77fcde0-1589259155.bundle cksum=6F0874F9DA123EA345D25A77F6D3CAFA alreadyin=0&lt;BR /&gt;
05-18-2020 07:31:58.235 +0000 ERROR CMSlave - event=move downloaded bundle to slave-apps failed with err="failed to remove dir=D:\Splunk\etc\slave-apps.old (There are no more files.)" even after multiple attempts, Exiting..&lt;BR /&gt;
05-18-2020 07:31:58.235 +0000 ERROR loader - Failed to download bundle from master, err="failed to remove dir=D:\Splunk\etc\slave-apps.old (There are no more files.)", Won't start splunkd.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 05:27:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-Splunkd-services-are-not-able-to-run/m-p/498665#M84986</guid>
      <dc:creator>phanichintha</dc:creator>
      <dc:date>2020-09-30T05:27:51Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer Splunkd services are not able to run</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-Splunkd-services-are-not-able-to-run/m-p/498666#M84987</link>
      <description>&lt;P&gt;Hello @phanichintha&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;ERROR loader - Failed to download bundle from master, err="failed to remove dir=D:\Splunk\etc\slave-apps.old (There are no more files.)", Won't start splunkd.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;remove &lt;CODE&gt;D:\Splunk\etc\slave-apps.old&lt;/CODE&gt; folder and try again&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2020 13:27:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-Splunkd-services-are-not-able-to-run/m-p/498666#M84987</guid>
      <dc:creator>PavelP</dc:creator>
      <dc:date>2020-05-18T13:27:31Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer Splunkd services are not able to run</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-Splunkd-services-are-not-able-to-run/m-p/498667#M84988</link>
      <description>&lt;P&gt;Hello PaveIP thank you so much for your answer, after removed &lt;STRONG&gt;D:\Splunk\etc\slave-apps.old&lt;/STRONG&gt; its restared.&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2020 14:13:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-Splunkd-services-are-not-able-to-run/m-p/498667#M84988</guid>
      <dc:creator>phanichintha</dc:creator>
      <dc:date>2020-05-18T14:13:00Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer Splunkd services are not able to run</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-Splunkd-services-are-not-able-to-run/m-p/498668#M84989</link>
      <description>&lt;P&gt;PavelP i have another question actually i stuck with something, can you please check if you have an idea about this.&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/821635/splunk-add-on-for-unix-and-linux-pssh-kafka-logs-a.html"&gt;https://answers.splunk.com/answers/821635/splunk-add-on-for-unix-and-linux-pssh-kafka-logs-a.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2020 14:18:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-Splunkd-services-are-not-able-to-run/m-p/498668#M84989</guid>
      <dc:creator>phanichintha</dc:creator>
      <dc:date>2020-05-18T14:18:32Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer Splunkd services are not able to run</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-Splunkd-services-are-not-able-to-run/m-p/498669#M84990</link>
      <description>&lt;P&gt;I'll check it, Please accept the previous answer if it solved your query.&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2020 14:21:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-Splunkd-services-are-not-able-to-run/m-p/498669#M84990</guid>
      <dc:creator>PavelP</dc:creator>
      <dc:date>2020-05-18T14:21:41Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer Splunkd services are not able to run</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-Splunkd-services-are-not-able-to-run/m-p/498670#M84991</link>
      <description>&lt;P&gt;How to accept answer here, i didn't see any popup. can you help out.&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2020 14:51:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-Splunkd-services-are-not-able-to-run/m-p/498670#M84991</guid>
      <dc:creator>phanichintha</dc:creator>
      <dc:date>2020-05-18T14:51:54Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer Splunkd services are not able to run</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-Splunkd-services-are-not-able-to-run/m-p/498671#M84992</link>
      <description>&lt;P&gt;please press "accept " link, it is located just after my answer in the same line with "Add comment · award points ·  accept". Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2020 15:26:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-Splunkd-services-are-not-able-to-run/m-p/498671#M84992</guid>
      <dc:creator>PavelP</dc:creator>
      <dc:date>2020-05-18T15:26:52Z</dc:date>
    </item>
  </channel>
</rss>

