<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Getting this error - then Splunkd crashes.. in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Getting-this-error-then-Splunkd-crashes/m-p/22420#M242</link>
    <description>&lt;P&gt;It looks like you have a corrupt index (_internal).&lt;BR /&gt;
You can run this command to check the index:&lt;/P&gt;

&lt;P&gt;To check the metadata use this.&lt;/P&gt;

&lt;P&gt;$SPLUNK/bin/splunk stop&lt;/P&gt;

&lt;P&gt;$SPLUNK/bin/splunk cmd splunkd fsck --index _internal&lt;/P&gt;

&lt;P&gt;To repair the metadata use this.&lt;/P&gt;

&lt;P&gt;$SPLUNK/bin/splunk stop&lt;/P&gt;

&lt;P&gt;$SPLUNK/bin/splunk cmd splunkd fsck --index _internal --mode metadata --repair&lt;/P&gt;

&lt;P&gt;To rebuild the bucket use this.&lt;/P&gt;

&lt;P&gt;$SPLUNK/bin/splunk stop&lt;/P&gt;

&lt;P&gt;$SPLUNK/bin/splunk rebuild $SPLUNK/bin/splunk rebuild $SPLUNK/bin/splunk/var/lib/splunk/_internal/pathtobadbucket&lt;/P&gt;

&lt;P&gt;Here is a link to a page that describes how to go about repairing indexes.&lt;BR /&gt;
&lt;A href="http://wiki.splunk.com/Check_and_Repair_Metadata"&gt;http://wiki.splunk.com/Check_and_Repair_Metadata&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 01 Aug 2013 18:37:21 GMT</pubDate>
    <dc:creator>lukejadamec</dc:creator>
    <dc:date>2013-08-01T18:37:21Z</dc:date>
    <item>
      <title>Getting this error - then Splunkd crashes..</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Getting-this-error-then-Splunkd-crashes/m-p/22419#M241</link>
      <description>&lt;P&gt;Error in 'databasePartitionPolicy': Failed to read 1 event(s) from rawdata in bucket '_internal~235~8AD95516-6DE5-4CCF-82AA-19FD5902414E'. Rawdata may be corrupt, see search.log&lt;/P&gt;

&lt;P&gt;I poked around here, just want to be sure that whatever I do doesn't destroy my instance.&lt;/P&gt;

&lt;P&gt;Any direction/suggestions would be greatly appreciated.&lt;/P&gt;

&lt;P&gt;Cheers,&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2013 18:16:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Getting-this-error-then-Splunkd-crashes/m-p/22419#M241</guid>
      <dc:creator>edenzler</dc:creator>
      <dc:date>2013-08-01T18:16:36Z</dc:date>
    </item>
    <item>
      <title>Re: Getting this error - then Splunkd crashes..</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Getting-this-error-then-Splunkd-crashes/m-p/22420#M242</link>
      <description>&lt;P&gt;It looks like you have a corrupt index (_internal).&lt;BR /&gt;
You can run this command to check the index:&lt;/P&gt;

&lt;P&gt;To check the metadata use this.&lt;/P&gt;

&lt;P&gt;$SPLUNK/bin/splunk stop&lt;/P&gt;

&lt;P&gt;$SPLUNK/bin/splunk cmd splunkd fsck --index _internal&lt;/P&gt;

&lt;P&gt;To repair the metadata use this.&lt;/P&gt;

&lt;P&gt;$SPLUNK/bin/splunk stop&lt;/P&gt;

&lt;P&gt;$SPLUNK/bin/splunk cmd splunkd fsck --index _internal --mode metadata --repair&lt;/P&gt;

&lt;P&gt;To rebuild the bucket use this.&lt;/P&gt;

&lt;P&gt;$SPLUNK/bin/splunk stop&lt;/P&gt;

&lt;P&gt;$SPLUNK/bin/splunk rebuild $SPLUNK/bin/splunk rebuild $SPLUNK/bin/splunk/var/lib/splunk/_internal/pathtobadbucket&lt;/P&gt;

&lt;P&gt;Here is a link to a page that describes how to go about repairing indexes.&lt;BR /&gt;
&lt;A href="http://wiki.splunk.com/Check_and_Repair_Metadata"&gt;http://wiki.splunk.com/Check_and_Repair_Metadata&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2013 18:37:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Getting-this-error-then-Splunkd-crashes/m-p/22420#M242</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2013-08-01T18:37:21Z</dc:date>
    </item>
    <item>
      <title>Re: Getting this error - then Splunkd crashes..</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Getting-this-error-then-Splunkd-crashes/m-p/22421#M243</link>
      <description>&lt;P&gt;check also here for more / additional help / solution;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://answers.splunk.com/answers/80882/corrupted-bucket-journal"&gt;http://answers.splunk.com/answers/80882/corrupted-bucket-journal&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2014 10:09:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Getting-this-error-then-Splunkd-crashes/m-p/22421#M243</guid>
      <dc:creator>lmyrefelt</dc:creator>
      <dc:date>2014-02-11T10:09:03Z</dc:date>
    </item>
  </channel>
</rss>

