<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can you help me with the following error that showed up after restarting the server: &amp;quot;Could not create path D:\Splunk\cisco\db appearing in indexes.conf: 3&amp;quot; in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Can-you-help-me-with-the-following-error-that-showed-up-after/m-p/433151#M3636</link>
    <description>&lt;P&gt;I restarted my server, and the Splunk web GUI didn't load up. My other servers and search heads load up, just not this particular search head. I know the issue is meant to be multiple indexes of the same thing, but I can't seem to see which one would be the problem child. This is the error i continually get every time i try, and either manually restart splunk services or restart the machine again. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;12-10-2018 15:35:27.962 +0000 INFO  loader - win-service: Starting as a Windows service: will run various system checks first...
12-10-2018 15:35:27.962 +0000 INFO  loader - win-service: Splunk starting as a local administrator
12-10-2018 15:35:27.962 +0000 INFO  loader - Automatic migration of modular inputs
12-10-2018 15:35:36.814 +0000 ERROR loader - win-service: Error running pre-flight-checks (_pclose returned 10).
12-10-2018 15:35:36.814 +0000 ERROR loader - win-service: Here is the output from running pre-flight-checks:
12-10-2018 15:35:36.814 +0000 ERROR loader - Could not create path D:\Splunk\cisco\db appearing in indexes.conf: 3
12-10-2018 15:35:36.814 +0000 ERROR loader -
12-10-2018 15:35:36.814 +0000 ERROR loader -  Checking critical directories... Done
12-10-2018 15:35:36.814 +0000 ERROR loader -  Checking indexes...
12-10-2018 15:35:36.814 +0000 ERROR loader - Validating databases (splunkd validatedb) failed with code '1'.  If you cannot resolve the issue(s) above after consulting documentation, please file a case online at &lt;A href="http://www.splunk.com/page/submit_issue" target="test_blank"&gt;http://www.splunk.com/page/submit_issue&lt;/A&gt;
12-10-2018 15:35:36.814 +0000 ERROR loader - &amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt; EOF (pre-flight-checks)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;any help is greatly appreciated&lt;/P&gt;

&lt;P&gt;Willsy&lt;/P&gt;</description>
    <pubDate>Mon, 10 Dec 2018 18:43:02 GMT</pubDate>
    <dc:creator>willsy</dc:creator>
    <dc:date>2018-12-10T18:43:02Z</dc:date>
    <item>
      <title>Can you help me with the following error that showed up after restarting the server: "Could not create path D:\Splunk\cisco\db appearing in indexes.conf: 3"</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Can-you-help-me-with-the-following-error-that-showed-up-after/m-p/433151#M3636</link>
      <description>&lt;P&gt;I restarted my server, and the Splunk web GUI didn't load up. My other servers and search heads load up, just not this particular search head. I know the issue is meant to be multiple indexes of the same thing, but I can't seem to see which one would be the problem child. This is the error i continually get every time i try, and either manually restart splunk services or restart the machine again. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;12-10-2018 15:35:27.962 +0000 INFO  loader - win-service: Starting as a Windows service: will run various system checks first...
12-10-2018 15:35:27.962 +0000 INFO  loader - win-service: Splunk starting as a local administrator
12-10-2018 15:35:27.962 +0000 INFO  loader - Automatic migration of modular inputs
12-10-2018 15:35:36.814 +0000 ERROR loader - win-service: Error running pre-flight-checks (_pclose returned 10).
12-10-2018 15:35:36.814 +0000 ERROR loader - win-service: Here is the output from running pre-flight-checks:
12-10-2018 15:35:36.814 +0000 ERROR loader - Could not create path D:\Splunk\cisco\db appearing in indexes.conf: 3
12-10-2018 15:35:36.814 +0000 ERROR loader -
12-10-2018 15:35:36.814 +0000 ERROR loader -  Checking critical directories... Done
12-10-2018 15:35:36.814 +0000 ERROR loader -  Checking indexes...
12-10-2018 15:35:36.814 +0000 ERROR loader - Validating databases (splunkd validatedb) failed with code '1'.  If you cannot resolve the issue(s) above after consulting documentation, please file a case online at &lt;A href="http://www.splunk.com/page/submit_issue" target="test_blank"&gt;http://www.splunk.com/page/submit_issue&lt;/A&gt;
12-10-2018 15:35:36.814 +0000 ERROR loader - &amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt; EOF (pre-flight-checks)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;any help is greatly appreciated&lt;/P&gt;

&lt;P&gt;Willsy&lt;/P&gt;</description>
      <pubDate>Mon, 10 Dec 2018 18:43:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Can-you-help-me-with-the-following-error-that-showed-up-after/m-p/433151#M3636</guid>
      <dc:creator>willsy</dc:creator>
      <dc:date>2018-12-10T18:43:02Z</dc:date>
    </item>
    <item>
      <title>Re: Can you help me with the following error that showed up after restarting the server: "Could not create path D:\Splunk\cisco\db appearing in indexes.conf: 3"</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Can-you-help-me-with-the-following-error-that-showed-up-after/m-p/433152#M3637</link>
      <description>&lt;P&gt;@Willsy: It looks like your indexes are not consistent across all instances(including your search-head), run a btool on your search-head for indexes.conf, and also look for any errors on the Search-head _internal logs.&lt;BR /&gt;
Compare other search-head configs with this search-head.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;##check any invalid key-stanzas
$SPLUNK_HOME/bin/splunk cmd btool check 
$SPLUNK_HOME/bin/splunk  cmd btool indexes list --debug
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 10 Dec 2018 19:03:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Can-you-help-me-with-the-following-error-that-showed-up-after/m-p/433152#M3637</guid>
      <dc:creator>prakash007</dc:creator>
      <dc:date>2018-12-10T19:03:42Z</dc:date>
    </item>
    <item>
      <title>Re: Can you help me with the following error that showed up after restarting the server: "Could not create path D:\Splunk\cisco\db appearing in indexes.conf: 3"</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Can-you-help-me-with-the-following-error-that-showed-up-after/m-p/433153#M3638</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;could be a permission issue, does the account running splunk have access to D:\Splunk\cisco\db?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Dec 2018 19:12:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Can-you-help-me-with-the-following-error-that-showed-up-after/m-p/433153#M3638</guid>
      <dc:creator>dkeck</dc:creator>
      <dc:date>2018-12-10T19:12:29Z</dc:date>
    </item>
    <item>
      <title>Re: Can you help me with the following error that showed up after restarting the server: "Could not create path D:\Splunk\cisco\db appearing in indexes.conf: 3"</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Can-you-help-me-with-the-following-error-that-showed-up-after/m-p/433154#M3639</link>
      <description>&lt;P&gt;This is what i recieved from btool, it doesnt look as though anything is wrong. &lt;/P&gt;

&lt;P&gt;C:\Program Files\Splunk\etc\system\local\indexes.conf   [cisco]&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf archiver.enableDataArchive = false&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf archiver.maxDataArchiveRetentionPeriod = 0&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf assureUTF8 = false&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf bucketRebuildMemoryHint = auto&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\local\indexes.conf   coldPath = D:\Splunk\cisco\colddb&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf coldPath.maxDataSizeMB = 0&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf coldToFrozenDir =&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf coldToFrozenScript =&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf compressRawdata = true&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf datatype = event&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf defaultDatabase = main&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf enableDataIntegrityControl = false&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf enableOnlineBucketRepair = true&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf enableRealtimeSearch = true&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf enableTsidxReduction = false&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\local\indexes.conf   frozenTimePeriodInSecs = 2592000&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\local\indexes.conf   homePath = D:\Splunk\cisco\db&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf homePath.maxDataSizeMB = 0&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf hotBucketTimeRefreshInterval = 10&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf indexThreads = auto&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf journalCompression = gzip&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf maxBloomBackfillBucketAge = 30d&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf maxBucketSizeCacheEntries = 0&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf maxConcurrentOptimizes = 6&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\local\indexes.conf   maxDataSize = auto&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf maxGlobalDataSizeMB = 0&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf maxHotBuckets = 3&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf maxHotIdleSecs = 0&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\local\indexes.conf   maxHotSpanSecs = 432000&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf maxMemMB = 5&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf maxMetaEntries = 1000000&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf maxRunningProcessGroups = 8&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf maxRunningProcessGroupsLowPriority = 1&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf maxTimeUnreplicatedNoAcks = 300&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf maxTimeUnreplicatedWithAcks = 60&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf maxTotalDataSizeMB = 500000&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf maxWarmDBCount = 300&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf memPoolMB = auto&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf minHotIdleSecsBeforeForceRoll = auto&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf minRawFileSyncSecs = disable&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf minStreamGroupQueueSize = 2000&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf partialServiceMetaPeriod = 0&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf processTrackerServiceInterval = 1&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf quarantineFutureSecs = 2592000&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf quarantinePastSecs = 77760000&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf rawChunkSizeBytes = 131072&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\local\indexes.conf   repFactor = auto&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf rotatePeriodInSecs = 60&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf rtRouterQueueSize = 10000&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf rtRouterThreads = 0&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf selfStorageThreads = 2&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf serviceInactiveIndexesPeriod = 60&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf serviceMetaPeriod = 25&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf serviceOnlyAsNeeded = true&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf serviceSubtaskTimingPeriod = 30&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf splitByIndexKeys =&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf streamingTargetTsidxSyncPeriodMsec = 5000&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf suppressBannerList =&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf suspendHotRollByDeleteQuery = false&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf sync = 0&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\default\indexes.conf syncMeta = true&lt;BR /&gt;
C:\Program Files\Splunk\etc\system\local\indexes.conf   thawedPath = D:\Splunk\cisco\thaweddb&lt;/P&gt;</description>
      <pubDate>Tue, 11 Dec 2018 09:31:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Can-you-help-me-with-the-following-error-that-showed-up-after/m-p/433154#M3639</guid>
      <dc:creator>willsy</dc:creator>
      <dc:date>2018-12-11T09:31:18Z</dc:date>
    </item>
    <item>
      <title>Re: Can you help me with the following error that showed up after restarting the server: "Could not create path D:\Splunk\cisco\db appearing in indexes.conf: 3"</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Can-you-help-me-with-the-following-error-that-showed-up-after/m-p/433155#M3640</link>
      <description>&lt;P&gt;@prakash007 i have ran btools with the commands you have given, there was no issues, the indexes.conf for cisco were correct with no errors, i have tried to attach the output for my cisco stanzas and file path but it seemed ok. &lt;/P&gt;

&lt;P&gt;@dkeck i have also tried your comment, i deleted the original cisco db D:\Splunk\cisco\db (it didnt have anything of value in as its new and in test) but to prove access and permissions i restarted my cluster and the D:\Splunk\cisco\db was there again. i then viewed permissions on the files and i have system properties so thats all good. &lt;/P&gt;

&lt;P&gt;to you both, i am not wholly sure where to go from now on, unless i delete the cisco app as a whole and potentially start again. thoughts? or is there anything else i could try? &lt;/P&gt;

&lt;P&gt;many thanks in advance &lt;/P&gt;</description>
      <pubDate>Tue, 11 Dec 2018 11:49:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Can-you-help-me-with-the-following-error-that-showed-up-after/m-p/433155#M3640</guid>
      <dc:creator>willsy</dc:creator>
      <dc:date>2018-12-11T11:49:21Z</dc:date>
    </item>
    <item>
      <title>Re: Can you help me with the following error that showed up after restarting the server: "Could not create path D:\Splunk\cisco\db appearing in indexes.conf: 3"</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Can-you-help-me-with-the-following-error-that-showed-up-after/m-p/433156#M3641</link>
      <description>&lt;P&gt;@willsy: so, you don't see any output when you run Splunk cmd btool check..??&lt;BR /&gt;
It looks like the output you posted is from splunk cmd btool indexes list --debug.&lt;/P&gt;

&lt;P&gt;what version of splunk are you on..??&lt;/P&gt;

&lt;P&gt;Check your SPLUNK_DB environment variable, look at this splunk answer if it helps...&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/94428/error-warning-cannot-create-new-path-for-index-when-starting-splunk.html"&gt;https://answers.splunk.com/answers/94428/error-warning-cannot-create-new-path-for-index-when-starting-splunk.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Dec 2018 15:28:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Can-you-help-me-with-the-following-error-that-showed-up-after/m-p/433156#M3641</guid>
      <dc:creator>prakash007</dc:creator>
      <dc:date>2018-12-11T15:28:19Z</dc:date>
    </item>
  </channel>
</rss>

