<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk not start in Installation</title>
    <link>https://community.splunk.com/t5/Installation/splunk-not-start/m-p/470540#M10302</link>
    <description>&lt;P&gt;We solve it, just restart Splunk, Splunk web services with local administrator privileges&lt;/P&gt;</description>
    <pubDate>Sun, 10 Nov 2019 04:11:11 GMT</pubDate>
    <dc:creator>givehchin</dc:creator>
    <dc:date>2019-11-10T04:11:11Z</dc:date>
    <item>
      <title>splunk not start</title>
      <link>https://community.splunk.com/t5/Installation/splunk-not-start/m-p/470530#M10292</link>
      <description>&lt;P&gt;hello&lt;BR /&gt;
recently my Splunk not start, it happens suddenly,after i notice splunk web not work,login to windows server and see it crash and have auto restart,after that i start splunk but get this :&lt;BR /&gt;
Checking prerequisites...&lt;BR /&gt;
        Checking http port [8000]: open&lt;BR /&gt;
        Checking mgmt port [8089]: open&lt;BR /&gt;
        Checking appserver port [127.0.0.1:8065]: open&lt;BR /&gt;
        Checking kvstore port [8191]: open&lt;BR /&gt;
        Checking configuration...  Done.&lt;BR /&gt;
        Checking critical directories...        Done&lt;BR /&gt;
        Checking indexes...&lt;BR /&gt;
Failed to determine if running as service user: LookupAccountName: No mapping between account names and security IDs was done.&lt;BR /&gt;
                (skipping validation of index paths because not running as ASADC\Mediterranean)&lt;BR /&gt;
                Validated: _audit _internal _introspection _telemetry _thefishbucket history main msad mssql perfmon summary vmware-esxilog vmware-inv vmware-perf vmware-taskevent vmware-vclog windows wineventlog winevents&lt;BR /&gt;
        Done&lt;BR /&gt;
        Checking filesystem compatibility...  Done&lt;BR /&gt;
        Checking conf files for problems...&lt;BR /&gt;
        Done&lt;BR /&gt;
        Checking default conf files for edits...&lt;BR /&gt;
        Validating installed files against hashes from 'C:\Program Files\Splunk\splunk-7.1.2-a0c72a66db66-windows-64-manifest'&lt;BR /&gt;
File 'C:\Program Files\Splunk\etc/system/default/indexes.conf' changed.&lt;BR /&gt;
File 'C:\Program Files\Splunk\etc/system/default/inputs.conf' changed.&lt;BR /&gt;
File 'C:\Program Files\Splunk\etc/system/default/limits.conf' changed.&lt;BR /&gt;
        Problems were found, please review your files and move customizations to local&lt;BR /&gt;
All preliminary checks passed.&lt;/P&gt;

&lt;P&gt;Starting splunk server daemon (splunkd)...&lt;/P&gt;

&lt;P&gt;Splunkd: Stopped&lt;/P&gt;

&lt;P&gt;what can i do?i chek log file of splunk and fined this :&lt;BR /&gt;
10-26-2019 08:02:54.889 +0330 ERROR StreamGroup - unexpected rc=1 from IndexableValue-&amp;gt;index&lt;BR /&gt;
10-26-2019 08:02:54.904 +0330 ERROR STMgr - dir='D:\Warm\defaultdb\db\hot_v1_10953' out of memory failure rc=1 warm_rc[-2,8] from st_txn_start&lt;BR /&gt;
10-26-2019 08:02:54.904 +0330 ERROR StreamGroup - unexpected rc=1 from IndexableValue-&amp;gt;index&lt;BR /&gt;
10-26-2019 08:02:54.904 +0330 ERROR STMgr - dir='D:\Warm\defaultdb\db\hot_v1_10953' out of memory failure rc=1 warm_rc[-2,8] from st_txn_start&lt;BR /&gt;
10-26-2019 08:02:54.904 +0330 ERROR StreamGroup - unexpected rc=1 from IndexableValue-&amp;gt;index&lt;BR /&gt;
10-26-2019 08:02:54.904 +0330 ERROR STMgr - dir='D:\Warm\defaultdb\db\hot_v1_10953' out of memory failure rc=1 warm_rc[-2,8] from st_txn_start&lt;BR /&gt;
10-26-2019 08:02:54.920 +0330 ERROR STMgr - dir='D:\Warm\defaultdb\db\hot_v1_10953' out of memory failure rc=1 warm_rc[-2,8] from st_txn_start&lt;BR /&gt;
10-26-2019 08:02:54.920 +0330 ERROR StreamGroup - unexpected rc=1 from IndexableValue-&amp;gt;index&lt;BR /&gt;
10-26-2019 08:02:54.920 +0330 ERROR STMgr - dir='D:\Warm\defaultdb\db\hot_v1_10953' out of memory failure rc=1 warm_rc[-2,8] from st_txn_start&lt;BR /&gt;
10-26-2019 08:02:54.920 +0330 ERROR StreamGroup - unexpected rc=1 from IndexableValue-&amp;gt;index&lt;BR /&gt;
10-26-2019 08:02:54.920 +0330 ERROR STMgr - dir='D:\Warm\defaultdb\db\hot_v1_10953' out of memory failure rc=1 warm_rc[-2,8] from st_txn_start&lt;BR /&gt;
10-26-2019 08:02:54.920 +0330 ERROR StreamGroup - unexpected rc=1 from IndexableValue-&amp;gt;index&lt;BR /&gt;
10-26-2019 08:02:54.935 +0330 ERROR STMgr - dir='D:\Warm\defaultdb\db\hot_v1_10953' out of memory failure rc=1 warm_rc[-2,8] from st_txn_start&lt;BR /&gt;
10-26-2019 08:02:54.935 +0330 ERROR StreamGroup - unexpected rc=1 from IndexableValue-&amp;gt;index&lt;BR /&gt;
10-26-2019 08:02:54.935 +0330 ERROR STMgr - dir='D:\Warm\defaultdb\db\hot_v1_10953' out of memory failure rc=1 warm_rc[-2,8] from st_txn_start&lt;BR /&gt;
10-26-2019 08:02:54.935 +0330 ERROR StreamGroup - unexpected rc=1 from IndexableValue-&amp;gt;index&lt;BR /&gt;
10-26-2019 08:02:54.935 +0330 ERROR STMgr - dir='D:\Warm\defaultdb\db\hot_v1_10953' out of memory failure rc=1 warm_rc[-2,8] from st_txn_start&lt;BR /&gt;
10-26-2019 08:02:54.935 +0330 ERROR StreamGroup - unexpected rc=1 from IndexableValue-&amp;gt;index&lt;BR /&gt;
10-26-2019 08:02:54.967 +0330 ERROR ExecProcessor - message from ""C:\Program Files\Splunk\bin\splunk-admon.exe"" splunk-admon - ADGetFullServerPath: Failed to bind to root 'LDAP://pri02.eng.ad.splunk.com/rootDSE': err='0x8007203a' - 'The server is not operational.'&lt;BR /&gt;
10-26-2019 08:02:54.967 +0330 ERROR ExecProcessor - message from ""C:\Program Files\Splunk\bin\splunk-admon.exe"" splunk-admon - ADGetFullServerPath: Failed to bind to root 'LDAP://pri01.eng.ad.splunk.com/rootDSE': err='0x8007203a' - 'The server is not operational.'&lt;BR /&gt;
10-26-2019 08:02:54.967 +0330 ERROR ExecProcessor - message from ""C:\Program Files\Splunk\bin\splunk-admon.exe"" splunk-admon - ADGetServerPath: Failed to bind to root: err='0x8007203a' - 'The server is not operational.'&lt;BR /&gt;
10-26-2019 08:02:54.967 +0330 ERROR ExecProcessor - message from ""C:\Program Files\Splunk\bin\splunk-admon.exe"" splunk-admon - AdEventCollector::GetDCAttributes: Failed to get AD server path.&lt;BR /&gt;
10-26-2019 08:02:54.967 +0330 ERROR ExecProcessor - message from ""C:\Program Files\Splunk\bin\splunk-admon.exe"" splunk-admon - AdEventCollector::InitCollector: LoadContextState failed: (0x80004005)Unspecified error -- attempting to reload server path&lt;BR /&gt;
10-26-2019 08:02:54.967 +0330 ERROR ExecProcessor - message from ""C:\Program Files\Splunk\bin\splunk-admon.exe"" splunk-admon - ADGetServerPath: Failed to bind to root: err='0x8007203a' - 'The server is not operational.'&lt;BR /&gt;
10-26-2019 08:02:54.967 +0330 ERROR ExecProcessor - message from ""C:\Program Files\Splunk\bin\splunk-admon.exe"" splunk-admon - AdEventCollector::GetDCAttributes: Failed to get AD server path.&lt;BR /&gt;
10-26-2019 08:02:54.967 +0330 ERROR ExecProcessor - message from ""C:\Program Files\Splunk\bin\splunk-admon.exe"" splunk-admon - AdEventCollector::InitCollector: LoadContextState failed: (0x80004005)Unspecified error -- attempting to reload server path&lt;BR /&gt;
10-26-2019 08:02:54.967 +0330 ERROR ExecProcessor - message from ""C:\Program Files\Splunk\bin\splunk-admon.exe"" splunk-admon - AdQuery::OutputStartEvent: Failed to search attributes of root object: err='0xa'&lt;BR /&gt;
10-26-2019 08:02:54.967 +0330 ERROR ExecProcessor - message from ""C:\Program Files\Splunk\bin\splunk-admon.exe"" splunk-admon - AdEventCollector::OutputStartEvent: Failed in OutputStartEvent,&lt;BR /&gt;
10-26-2019 08:02:54.967 +0330 ERROR ExecProcessor - message from ""C:\Program Files\Splunk\bin\splunk-admon.exe"" splunk-admon - AdEventCollector::InitCollector: LoadContextState failed again with DCName='Asa-Dc.AsaDc.local': (0x80004005)Unspecified error -- no more retries&lt;BR /&gt;
10-26-2019 08:02:54.967 +0330 ERROR ExecProcessor - message from ""C:\Program Files\Splunk\bin\splunk-admon.exe"" splunk-admon - ADMonitor::init: Failed to initialize Active Directory usn context.&lt;BR /&gt;
10-26-2019 08:02:54.967 +0330 ERROR ExecProcessor - message from ""C:\Program Files\Splunk\bin\splunk-admon.exe"" splunk-admon - ADMonitorThread::launchADMonitor: Failed to initialize ADMonitor='admon://SecondTargetDC', targedDC='pri02.eng.ad.splunk.com'&lt;BR /&gt;
10-26-2019 08:02:54.967 +0330 ERROR ExecProcessor - message from ""C:\Program Files\Splunk\bin\splunk-admon.exe"" splunk-admon - AdQuery::OutputStartEvent: Failed to search attributes of root object: err='0xa'&lt;BR /&gt;
10-26-2019 08:02:54.967 +0330 ERROR ExecProcessor - message from ""C:\Program Files\Splunk\bin\splunk-admon.exe"" splunk-admon - AdEventCollector::OutputStartEvent: Failed in OutputStartEvent,&lt;BR /&gt;
10-26-2019 08:02:54.967 +0330 ERROR ExecProcessor - message from ""C:\Program Files\Splunk\bin\splunk-admon.exe"" splunk-admon - AdEventCollector::InitCollector: LoadContextState failed again with DCName='Asa-Dc.AsaDc.local': (0x80004005)Unspecified error -- no more retries&lt;BR /&gt;
10-26-2019 08:02:54.967 +0330 ERROR ExecProcessor - message from ""C:\Program Files\Splunk\bin\splunk-admon.exe"" splunk-admon - ADMonitor::init: Failed to initialize Active Directory usn context.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:45:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/splunk-not-start/m-p/470530#M10292</guid>
      <dc:creator>givehchin</dc:creator>
      <dc:date>2020-09-30T02:45:29Z</dc:date>
    </item>
    <item>
      <title>Re: splunk not start</title>
      <link>https://community.splunk.com/t5/Installation/splunk-not-start/m-p/470531#M10293</link>
      <description>&lt;P&gt;What kind of instance is it. If it is an EC2, try stopping and starting the instance. Then go to the terminal and start the splunk.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2019 19:58:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/splunk-not-start/m-p/470531#M10293</guid>
      <dc:creator>vsai0718</dc:creator>
      <dc:date>2019-10-28T19:58:24Z</dc:date>
    </item>
    <item>
      <title>Re: splunk not start</title>
      <link>https://community.splunk.com/t5/Installation/splunk-not-start/m-p/470532#M10294</link>
      <description>&lt;P&gt;Did you upgrade to v8.0?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2019 21:28:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/splunk-not-start/m-p/470532#M10294</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-10-28T21:28:56Z</dc:date>
    </item>
    <item>
      <title>Re: splunk not start</title>
      <link>https://community.splunk.com/t5/Installation/splunk-not-start/m-p/470533#M10295</link>
      <description>&lt;P&gt;Several issues that could be related.&lt;BR /&gt;
Seems like could be a permissions issue of the user permissions Splunk as a service is running as&lt;BR /&gt;
I would check the password for the splunkd service if not using managed service accounts. The two  errors listed below points to this. &lt;/P&gt;

&lt;P&gt;Skipping validation of index paths  error due to not running as ASADC\Mediterranean&lt;BR /&gt;
Failed to determine if running as service user: LookupAccountName: No mapping between account names and security IDs was done.&lt;/P&gt;

&lt;P&gt;Another possibility looks like could be a GPO error and example of a fix for this is below.  Not sure what version of windows server that is running.&lt;BR /&gt;
&lt;A href="http://www.rebeladmin.com/2016/01/how-to-fix-error-no-mapping-between-account-names-and-security-ids-in-active-directory/"&gt;http://www.rebeladmin.com/2016/01/how-to-fix-error-no-mapping-between-account-names-and-security-ids-in-active-directory/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Another issue that could cause problems is placing changes in default not local directory - will cause issues anytime you update Splunk because changes will be overwritten.  &lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2019 22:27:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/splunk-not-start/m-p/470533#M10295</guid>
      <dc:creator>clintonburnett</dc:creator>
      <dc:date>2019-10-28T22:27:11Z</dc:date>
    </item>
    <item>
      <title>Re: splunk not start</title>
      <link>https://community.splunk.com/t5/Installation/splunk-not-start/m-p/470534#M10296</link>
      <description>&lt;P&gt;no, I do not upgrade it, can Splunk automatically update???&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 05:38:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/splunk-not-start/m-p/470534#M10296</guid>
      <dc:creator>givehchin</dc:creator>
      <dc:date>2019-10-30T05:38:13Z</dc:date>
    </item>
    <item>
      <title>Re: splunk not start</title>
      <link>https://community.splunk.com/t5/Installation/splunk-not-start/m-p/470535#M10297</link>
      <description>&lt;P&gt;I cant understand, what is EC2??? I stop all Splunk in task manager and start it again, nothing changed&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 05:39:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/splunk-not-start/m-p/470535#M10297</guid>
      <dc:creator>givehchin</dc:creator>
      <dc:date>2019-10-30T05:39:27Z</dc:date>
    </item>
    <item>
      <title>Re: splunk not start</title>
      <link>https://community.splunk.com/t5/Installation/splunk-not-start/m-p/470536#M10298</link>
      <description>&lt;P&gt;that error(mediteranian user) probably be there in past couple months&lt;/P&gt;

&lt;P&gt;I using Windows Server 2016&lt;/P&gt;

&lt;P&gt;does Splunk can automatically update?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 05:44:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/splunk-not-start/m-p/470536#M10298</guid>
      <dc:creator>givehchin</dc:creator>
      <dc:date>2019-10-30T05:44:28Z</dc:date>
    </item>
    <item>
      <title>Re: splunk not start</title>
      <link>https://community.splunk.com/t5/Installation/splunk-not-start/m-p/470537#M10299</link>
      <description>&lt;P&gt;I checked Splunk version from Splunk.version and splunk.exe,they show my current version 7.1.2 wich it mean not updated at all&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 06:07:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/splunk-not-start/m-p/470537#M10299</guid>
      <dc:creator>givehchin</dc:creator>
      <dc:date>2019-10-30T06:07:27Z</dc:date>
    </item>
    <item>
      <title>Re: splunk not start</title>
      <link>https://community.splunk.com/t5/Installation/splunk-not-start/m-p/470538#M10300</link>
      <description>&lt;P&gt;No, it cannot.&lt;/P&gt;</description>
      <pubDate>Sat, 09 Nov 2019 21:19:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/splunk-not-start/m-p/470538#M10300</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-11-09T21:19:22Z</dc:date>
    </item>
    <item>
      <title>Re: splunk not start</title>
      <link>https://community.splunk.com/t5/Installation/splunk-not-start/m-p/470539#M10301</link>
      <description>&lt;P&gt;It looks like Splunk is complaining about the Index values defined on your &lt;CODE&gt;D&lt;/CODE&gt; drive.  Is your &lt;CODE&gt;D&lt;/CODE&gt; drive mounted?  Is your &lt;CODE&gt;D&lt;/CODE&gt; drive full? If so, fix that and it shoud be OK.  The long term solution is to stop running your Splunk infrastructure (Indexers) on Windows OS:&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/516059/what-are-the-pain-points-with-deploying-your-splun.html"&gt;https://answers.splunk.com/answers/516059/what-are-the-pain-points-with-deploying-your-splun.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 09 Nov 2019 21:22:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/splunk-not-start/m-p/470539#M10301</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-11-09T21:22:25Z</dc:date>
    </item>
    <item>
      <title>Re: splunk not start</title>
      <link>https://community.splunk.com/t5/Installation/splunk-not-start/m-p/470540#M10302</link>
      <description>&lt;P&gt;We solve it, just restart Splunk, Splunk web services with local administrator privileges&lt;/P&gt;</description>
      <pubDate>Sun, 10 Nov 2019 04:11:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/splunk-not-start/m-p/470540#M10302</guid>
      <dc:creator>givehchin</dc:creator>
      <dc:date>2019-11-10T04:11:11Z</dc:date>
    </item>
    <item>
      <title>Re: splunk not start</title>
      <link>https://community.splunk.com/t5/Installation/splunk-not-start/m-p/470541#M10303</link>
      <description>&lt;P&gt;Great! Now come back and click &lt;CODE&gt;Accept&lt;/CODE&gt; on your answer to close the question and &lt;CODE&gt;UpVote&lt;/CODE&gt; any other answers or comments that helped you.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Nov 2019 14:10:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/splunk-not-start/m-p/470541#M10303</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-11-10T14:10:13Z</dc:date>
    </item>
  </channel>
</rss>

