<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk won't start after upgrading to 8.2.2 from 8.0.x in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Splunk-won-t-start-after-upgrading-to-8-2-2-from-8-0-x/m-p/565103#M10608</link>
    <description>&lt;P&gt;Have you taken a look at $SPLUNK_HOME/var/log/splunk/splunkd.log to get any hints as to what may be happening?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 27 Aug 2021 18:34:07 GMT</pubDate>
    <dc:creator>s2_splunk</dc:creator>
    <dc:date>2021-08-27T18:34:07Z</dc:date>
    <item>
      <title>Splunk won't start after upgrading to 8.2.2 from 8.0.x</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-won-t-start-after-upgrading-to-8-2-2-from-8-0-x/m-p/565102#M10607</link>
      <description>&lt;P&gt;After upgrading Splunk Enterprise to version 8.2.2 from 8.0.x, Splunk will not start on my Indexer/Search head. When I start it I get the following error:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jfontenot_0-1630088453234.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/15772iB4ED6C80859B435D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jfontenot_0-1630088453234.png" alt="jfontenot_0-1630088453234.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Any ideas on what could be causing this or places to check?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 18:21:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-won-t-start-after-upgrading-to-8-2-2-from-8-0-x/m-p/565102#M10607</guid>
      <dc:creator>jfontenot</dc:creator>
      <dc:date>2021-08-27T18:21:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk won't start after upgrading to 8.2.2 from 8.0.x</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-won-t-start-after-upgrading-to-8-2-2-from-8-0-x/m-p/565103#M10608</link>
      <description>&lt;P&gt;Have you taken a look at $SPLUNK_HOME/var/log/splunk/splunkd.log to get any hints as to what may be happening?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 18:34:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-won-t-start-after-upgrading-to-8-2-2-from-8-0-x/m-p/565103#M10608</guid>
      <dc:creator>s2_splunk</dc:creator>
      <dc:date>2021-08-27T18:34:07Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk won't start after upgrading to 8.2.2 from 8.0.x</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-won-t-start-after-upgrading-to-8-2-2-from-8-0-x/m-p/565110#M10609</link>
      <description>&lt;P&gt;When I start Splunk I get the following messages in $SPLUNK_HOME/var/log/splunk/splunkd.log.&lt;/P&gt;&lt;P&gt;08-27-2021 13:59:55.720 -0500 WARN DatabaseDirectoryManager [11664 SplunkdSpecificInitThread] - Unable to find a directory for db id=_internal~764~22C4282A-1F3D-4C0D-8517-152DB5BD0C86 with dir_name=hot_v1_764&lt;/P&gt;&lt;P&gt;hot/splunkdb/_internaldb/db' pendingBucketUpdates=1 innerLockTime=0.000. Reason='Getting directory for bid=_internal~764~22C4282A-1F3D-4C0D-8517-152DB5BD0C86 bucket map updated due to missing path="/mnt/hot/splunkdb/_internaldb/db/hot_v1_764"'&lt;/P&gt;&lt;P&gt;08-27-2021 13:59:55.722 -0500 INFO DatabaseDirectoryManager [11664 SplunkdSpecificInitThread] - Finished writing bucket manifest in hotWarmPath=/mnt/hot/splunkdb/_internaldb/db duration=0.001&lt;/P&gt;&lt;P&gt;08-27-2021 13:59:55.723 -0500 WARN DatabaseDirectoryManager [11664 SplunkdSpecificInitThread] - Unable to find a directory for db id=_internal~764~22C4282A-1F3D-4C0D-8517-152DB5BD0C86 with dir_name=hot_v1_764&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;08-27-2021 13:59:55.723 -0500 INFO DatabaseDirectoryManager [11664 SplunkdSpecificInitThread] - idx=_internal writing a bucket manifest in hotWarmPath='/mnt/hot/splunkdb/_internaldb/db' pendingBucketUpdates=1 innerLockTime=0.000. Reason='Getting directory for bid=_internal~764~22C4282A-1F3D-4C0D-8517-152DB5BD0C86 bucket map updated due to missing path="/mnt/hot/splunkdb/_internaldb/db/hot_v1_764"'&lt;/P&gt;&lt;P&gt;08-27-2021 13:59:55.725 -0500 INFO DatabaseDirectoryManager [11664 SplunkdSpecificInitThread] - Finished writing bucket manifest in hotWarmPath=/mnt/hot/splunkdb/_internaldb/db duration=0.002&lt;/P&gt;&lt;P&gt;08-27-2021 13:59:55.725 -0500 WARN DatabaseDirectoryManager [11664 SplunkdSpecificInitThread] - Unable to find a directory for db id=_internal~764~22C4282A-1F3D-4C0D-8517-152DB5BD0C86 with dir_name=hot_v1_764&lt;/P&gt;&lt;P&gt;08-27-2021 13:59:55.726 -0500 INFO DatabaseDirectoryManager [11664 SplunkdSpecificInitThread] - idx=_internal writing a bucket manifest in hotWarmPath='/mnt/hot/splunkdb/_internaldb/db' pendingBucketUpdates=1 innerLockTime=0.000. Reason='Getting directory for bid=_internal~764~22C4282A-1F3D-4C0D-8517-152DB5BD0C86 bucket map updated due to missing path="/mnt/hot/splunkdb/_internaldb/db/hot_v1_764"'&lt;/P&gt;&lt;P&gt;08-27-2021 13:59:55.727 -0500 INFO DatabaseDirectoryManager [11664 SplunkdSpecificInitThread] - Finished writing bucket manifest in hotWarmPath=/mnt/hot/splunkdb/_internaldb/db duration=0.001&lt;/P&gt;&lt;P&gt;08-27-2021 13:59:55.728 -0500 ERROR BucketMover [11664 SplunkdSpecificInitThread] - Unexpected failure to parse bucket='/mnt/cold/splunkdb/_internaldb/colddb/hot_v1_764'&lt;/P&gt;&lt;P&gt;DatabaseDirectoryManager [11664 SplunkdSpecificInitThread] - Unable to find a directory for db id=_internal&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 19:06:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-won-t-start-after-upgrading-to-8-2-2-from-8-0-x/m-p/565110#M10609</guid>
      <dc:creator>jfontenot</dc:creator>
      <dc:date>2021-08-27T19:06:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk won't start after upgrading to 8.2.2 from 8.0.x</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-won-t-start-after-upgrading-to-8-2-2-from-8-0-x/m-p/565161#M10610</link>
      <description>&lt;P&gt;Please check if exists /mnt/hot or &amp;nbsp;/mnt mount. &amp;nbsp;Also, check for permission for splunk user.&lt;/P&gt;</description>
      <pubDate>Sun, 29 Aug 2021 07:38:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-won-t-start-after-upgrading-to-8-2-2-from-8-0-x/m-p/565161#M10610</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-08-29T07:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk won't start after upgrading to 8.2.2 from 8.0.x</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-won-t-start-after-upgrading-to-8-2-2-from-8-0-x/m-p/565177#M10611</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233467"&gt;@jfontenot&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Verify all apps that expose web endpoints use Python3. Check each app's web.conf and Python scripts to confirm. Incompatible endpoints will prevent the app server from starting. EDIT: The mobile interface didn't display the other responses when I initially viewed the question. Apologies if you've already checked this.&lt;/P&gt;</description>
      <pubDate>Sun, 29 Aug 2021 17:41:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-won-t-start-after-upgrading-to-8-2-2-from-8-0-x/m-p/565177#M10611</guid>
      <dc:creator>tscroggins</dc:creator>
      <dc:date>2021-08-29T17:41:38Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk won't start after upgrading to 8.2.2 from 8.0.x</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-won-t-start-after-upgrading-to-8-2-2-from-8-0-x/m-p/565342#M10618</link>
      <description>&lt;P&gt;It looks to me like your filesystem is not mounted. When you created it did you add an entry to fstab?&lt;/P&gt;&lt;P&gt;Check if any files or directories are there: ls -la /mnt&lt;BR /&gt;Check fstab: cat /etc/fstab&lt;BR /&gt;If it isn't mount your filesystem: mount -a&lt;BR /&gt;If it is mounted check that it's not owned by root instead of your Splunk user: Same output from ls -la /mnt&lt;BR /&gt;Change user:group ownership to your Splunk user if necessary: chown -RP splunk:splunk /mnt/&lt;BR /&gt;(assuming your Splunk user/group is "splunk".&lt;/P&gt;</description>
      <pubDate>Tue, 31 Aug 2021 14:31:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-won-t-start-after-upgrading-to-8-2-2-from-8-0-x/m-p/565342#M10618</guid>
      <dc:creator>codebuilder</dc:creator>
      <dc:date>2021-08-31T14:31:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk won't start after upgrading to 8.2.2 from 8.0.x</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-won-t-start-after-upgrading-to-8-2-2-from-8-0-x/m-p/565710#M10641</link>
      <description>&lt;P&gt;You could change in `etc/splunk-launch.conf`:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="c"&gt;SPLUNK_DB=/tmp/splunk_db&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Just to see if you can get a clean start?&lt;/P&gt;&lt;P&gt;I'm probably wrong but it looks like there is a problem binding to port 8000? This could be caused by other errors, like a filesystem problem? I haven't looked at errors like this for years as I am only now making a comeback to the world of Splunk.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Sep 2021 19:05:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-won-t-start-after-upgrading-to-8-2-2-from-8-0-x/m-p/565710#M10641</guid>
      <dc:creator>ephemeric</dc:creator>
      <dc:date>2021-09-02T19:05:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk won't start after upgrading to 8.2.2 from 8.0.x</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-won-t-start-after-upgrading-to-8-2-2-from-8-0-x/m-p/575539#M10891</link>
      <description>&lt;P&gt;The Splunk hot buckets should not end up being in indexname/colddb but it did. You can try to move it back to indexname/db and see if it starts back successfully or move the hotbucket out of the colddb - move it to somewhere like tmp directory - it should come back.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 20:19:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-won-t-start-after-upgrading-to-8-2-2-from-8-0-x/m-p/575539#M10891</guid>
      <dc:creator>sylim_splunk</dc:creator>
      <dc:date>2021-11-18T20:19:52Z</dc:date>
    </item>
  </channel>
</rss>

