<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot create Index in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Cannot-create-Index/m-p/346599#M8014</link>
    <description>&lt;P&gt;Cold and Thawed paths aren't pointing to /var/splunkdata/security, at least the screenshot doesn't indicate it is.  Those paths still make use of $SPLUNK_DB, which isn't discernible from what was posted.&lt;/P&gt;

&lt;P&gt;You may need to define cold and thawed path explicity, unless $SPLUNK_DB is set to something that makes sense (has sufficient space and is writeable by the splunk user).&lt;/P&gt;</description>
    <pubDate>Fri, 15 Dec 2017 14:11:53 GMT</pubDate>
    <dc:creator>micahkemp</dc:creator>
    <dc:date>2017-12-15T14:11:53Z</dc:date>
    <item>
      <title>Cannot create Index</title>
      <link>https://community.splunk.com/t5/Installation/Cannot-create-Index/m-p/346597#M8012</link>
      <description>&lt;P&gt;Hi &lt;BR /&gt;
(I'm new to splunk )&lt;/P&gt;

&lt;P&gt;Environment: Splunk 7.1 / RHEL6.5&lt;/P&gt;

&lt;P&gt;I have create my own log file for test purposes / learning (its like a syslog log) and I can see the data in splunk. But when I try to create an index for it I get the error below, does anyone know what could be causing this ?&lt;/P&gt;

&lt;P&gt;ERROR MESSAGE: &lt;/P&gt;

&lt;P&gt;Data could not be written: /nobody/search/indexes/testosboot/thawedPath: $SPLUNK_DB/testosboot/thaweddb &lt;/P&gt;

&lt;P&gt;Rgds&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/4006i41B462B51172A03B/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;BR /&gt;
Dee&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2017 13:54:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Cannot-create-Index/m-p/346597#M8012</guid>
      <dc:creator>deepakc</dc:creator>
      <dc:date>2017-12-15T13:54:01Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot create Index</title>
      <link>https://community.splunk.com/t5/Installation/Cannot-create-Index/m-p/346598#M8013</link>
      <description>&lt;P&gt;Does the path&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;/var/splunkdata/security 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;exist and is it writable by the splunk user?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2017 14:06:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Cannot-create-Index/m-p/346598#M8013</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-12-15T14:06:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot create Index</title>
      <link>https://community.splunk.com/t5/Installation/Cannot-create-Index/m-p/346599#M8014</link>
      <description>&lt;P&gt;Cold and Thawed paths aren't pointing to /var/splunkdata/security, at least the screenshot doesn't indicate it is.  Those paths still make use of $SPLUNK_DB, which isn't discernible from what was posted.&lt;/P&gt;

&lt;P&gt;You may need to define cold and thawed path explicity, unless $SPLUNK_DB is set to something that makes sense (has sufficient space and is writeable by the splunk user).&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2017 14:11:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Cannot-create-Index/m-p/346599#M8014</guid>
      <dc:creator>micahkemp</dc:creator>
      <dc:date>2017-12-15T14:11:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot create Index</title>
      <link>https://community.splunk.com/t5/Installation/Cannot-create-Index/m-p/346600#M8015</link>
      <description>&lt;P&gt;thanks I did checked the permissions, and it was correct as I could write to the folder as the user ,  I uninstalled it all, rebooted, reinstalled 7.1 and after it was ok... (so I must have made a mistake somewhere and did have version 7.0 installed, which I uninstalled but did not reboot) &lt;/P&gt;

&lt;P&gt;thanks for the pointers&lt;/P&gt;

&lt;P&gt;Dee &lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2017 15:57:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Cannot-create-Index/m-p/346600#M8015</guid>
      <dc:creator>deepakc</dc:creator>
      <dc:date>2017-12-15T15:57:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot create Index</title>
      <link>https://community.splunk.com/t5/Installation/Cannot-create-Index/m-p/346601#M8016</link>
      <description>&lt;P&gt;thanks for the pointers, by uninstalling it and reinstalling, then checking the permissions, its working now&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2017 16:00:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Cannot-create-Index/m-p/346601#M8016</guid>
      <dc:creator>deepakc</dc:creator>
      <dc:date>2017-12-15T16:00:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot create Index</title>
      <link>https://community.splunk.com/t5/Installation/Cannot-create-Index/m-p/346602#M8017</link>
      <description>&lt;P&gt;I should have rebooted after uninstalling version 7.0 and then perform a clean install of version 7.1&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2017 16:02:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Cannot-create-Index/m-p/346602#M8017</guid>
      <dc:creator>deepakc</dc:creator>
      <dc:date>2017-12-15T16:02:19Z</dc:date>
    </item>
  </channel>
</rss>

