<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to fix failed indexer on Splunkd? in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-fix-failed-indexer-on-Splunkd/m-p/482483#M3979</link>
    <description>&lt;P&gt;Hello dear Skoelpin,&lt;/P&gt;

&lt;P&gt;in MC it showing me that 1 instances unreachable and it is that one indexer that are down.&lt;/P&gt;

&lt;P&gt;and when am checking if splunk process is running using ./splunk status it is showing me that splunkd is not running ,how to make it run again using CLI ?&lt;/P&gt;</description>
    <pubDate>Thu, 23 Apr 2020 17:42:20 GMT</pubDate>
    <dc:creator>pacifikn</dc:creator>
    <dc:date>2020-04-23T17:42:20Z</dc:date>
    <item>
      <title>How to fix failed indexer on Splunkd?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-fix-failed-indexer-on-Splunkd/m-p/482481#M3977</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;One Splunkd indexer is failing while other indexers are running.&lt;BR /&gt;I'm also getting a TCPOutAutoLB-0 error.&lt;/P&gt;
&lt;P&gt;How can I fix these issues?&lt;/P&gt;
&lt;P&gt;Thank you in Advance.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2020 23:12:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-fix-failed-indexer-on-Splunkd/m-p/482481#M3977</guid>
      <dc:creator>pacifikn</dc:creator>
      <dc:date>2020-06-05T23:12:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix failed indexer on Splunkd?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-fix-failed-indexer-on-Splunkd/m-p/482482#M3978</link>
      <description>&lt;P&gt;You're going to want to search to internal logs and the MC to identify why it stopped before doing anything else&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2020 16:38:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-fix-failed-indexer-on-Splunkd/m-p/482482#M3978</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2020-04-23T16:38:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix failed indexer on Splunkd?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-fix-failed-indexer-on-Splunkd/m-p/482483#M3979</link>
      <description>&lt;P&gt;Hello dear Skoelpin,&lt;/P&gt;

&lt;P&gt;in MC it showing me that 1 instances unreachable and it is that one indexer that are down.&lt;/P&gt;

&lt;P&gt;and when am checking if splunk process is running using ./splunk status it is showing me that splunkd is not running ,how to make it run again using CLI ?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2020 17:42:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-fix-failed-indexer-on-Splunkd/m-p/482483#M3979</guid>
      <dc:creator>pacifikn</dc:creator>
      <dc:date>2020-04-23T17:42:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix failed indexer on Splunkd?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-fix-failed-indexer-on-Splunkd/m-p/482484#M3980</link>
      <description>&lt;P&gt;I'd strongly recommend identifying why it stopped before starting it. While in the MC, go to Instances, then under "Action", select "Views" and checkout the performance and resource usage. You should then look in the internal index and identify any error messages it may have thrown before stopping. You can do this with a query like this &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal sourcetype=splunkd host=&amp;lt;YOUR INDEXER&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Look for any log levels that are not INFO and any messages along with it. After you've determine root cause and you still want to start it, ssh to the indexer and start it &lt;/P&gt;

&lt;P&gt;This assumes your splunk instance is under /opt&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;/opt/splunk/bin/splunk start
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 23 Apr 2020 18:39:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-fix-failed-indexer-on-Splunkd/m-p/482484#M3980</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2020-04-23T18:39:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix failed indexer on Splunkd?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-fix-failed-indexer-on-Splunkd/m-p/482485#M3981</link>
      <description>&lt;P&gt;Dear Skoelpin, thank you for your guidance,&lt;/P&gt;

&lt;P&gt;I have checked into the intrnal logs, i found out the below output logs which it seems abnormal,&lt;/P&gt;

&lt;P&gt;under Event&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;HR /&gt;

&lt;P&gt;04-23-2020 20:51:17.667 +0200 INFO TcpOutputProc - Connected to idx=host_Ip:9997 ,pset=0 , reuse=0. &lt;BR /&gt;
host=host_name source=/opt/splunkforwarder/var/log/splunk/splunkd.log  sourcetype=splunkd&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;04-23-2020 20:51:17.667 +0200 INFO TcpOutputProc - Closing Stream for idx=host_Ip:9997 &lt;BR /&gt;
host=host_name source=/opt/splunkforwarder/var/log/splunk/splunkd.log  sourcetype=splunkd&lt;/P&gt;

&lt;HR /&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;I see the above logs, how may i fix this?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 05:07:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-fix-failed-indexer-on-Splunkd/m-p/482485#M3981</guid>
      <dc:creator>pacifikn</dc:creator>
      <dc:date>2020-09-30T05:07:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix failed indexer on Splunkd?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-fix-failed-indexer-on-Splunkd/m-p/482486#M3982</link>
      <description>&lt;P&gt;Those are normal, keep looking. Perhaps filter down your query by including &lt;CODE&gt;log_level!="INFO"&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2020 19:07:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-fix-failed-indexer-on-Splunkd/m-p/482486#M3982</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2020-04-23T19:07:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix failed indexer on Splunkd?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-fix-failed-indexer-on-Splunkd/m-p/482487#M3983</link>
      <description>&lt;P&gt;Dear Skoelpin, addding log_level!="INFO" in search i got this:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;HR /&gt;

&lt;P&gt;04-23-2020 21:05:44.329 +0200 ERROR TcpOutputFd  - Connection to host_Ip:9997 failed &lt;BR /&gt;
host=host_name source=/opt/splunkforwarder/var/log/splunk/splunkd.log sourcetype=splunkd&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;04-23-2020 21:05:44.329 +0200 WARN TcpOutputFd  - Connect to host_Ip:9997 failed . Connection refused &lt;BR /&gt;
host=host_name source=/opt/splunkforwarder/var/log/splunk/splunkd.log sourcetype=splunkd&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;running the query i got this above logs and others but it's the same only hours are changed but same error.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Wed, 30 Sep 2020 05:07:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-fix-failed-indexer-on-Splunkd/m-p/482487#M3983</guid>
      <dc:creator>pacifikn</dc:creator>
      <dc:date>2020-09-30T05:07:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix failed indexer on Splunkd?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-fix-failed-indexer-on-Splunkd/m-p/482488#M3984</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/209306"&gt;@pacifikn&lt;/a&gt;,&lt;/P&gt;

&lt;P&gt;as &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/132691"&gt;@skoelpin&lt;/a&gt; suggested, check splunkd.log and other logs, particularly crash*log, &lt;STRONG&gt;on the failed indexer&lt;/STRONG&gt;. You will not find anything from the indexer on the MC if the indexer is down because it cannot send any logs to the MC.&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;check last lines in  $SPLUNK_HOME/var/log/splunk/splunkd.conf, especially with ERROR and WARN severity&lt;/LI&gt;
&lt;LI&gt;check if there are any crash*log in $SPLUNK_HOME/var/log/splunk/ folder&lt;/LI&gt;
&lt;LI&gt;run &lt;STRONG&gt;systemctl status Splunkd&lt;/STRONG&gt; if it is a systemd-enabled splunk&lt;/LI&gt;
&lt;LI&gt;run &lt;STRONG&gt;grep -i splunk /var/log/messages&lt;/STRONG&gt; &lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Let me know if you find something&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 05:05:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-fix-failed-indexer-on-Splunkd/m-p/482488#M3984</guid>
      <dc:creator>PavelP</dc:creator>
      <dc:date>2020-09-30T05:05:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix failed indexer on Splunkd?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-fix-failed-indexer-on-Splunkd/m-p/482489#M3985</link>
      <description>&lt;P&gt;@Dear PaveIP,&lt;BR /&gt;
@skoelpin ,&lt;/P&gt;

&lt;P&gt;Dear PaveIP ,i have run those command,&lt;/P&gt;

&lt;P&gt;1&amp;amp;2 command: &lt;/P&gt;

&lt;H2&gt; I have choose the splunkd.log.5 which is last one on the splunkd log but not last file in running the command, And by looking on WARN and INFO gives me this below output:&lt;/H2&gt;

&lt;P&gt;04-23-2020 20:51:17.667 +0200 INFO TcpOutputProc - Connected to idx=host_Ip:9997 ,pset=0 , reuse=0.&lt;/P&gt;

&lt;H2&gt;host=host_name source=/opt/splunkforwarder/var/log/splunk/splunkd.log sourcetype=splunkd&lt;/H2&gt;

&lt;P&gt;04-23-2020 21:05:44.329 +0200 WARN TcpOutputFd - Connect to host_Ip:9997 failed . Connection refused&lt;/P&gt;

&lt;H2&gt;host=host_name source=/opt/splunkforwarder/var/log/splunk/splunkd.log sourcetype=splunkd&lt;/H2&gt;

&lt;H2&gt;04-09-2020 07:26:01.921 +0200 IWARN LookupDataProvider - The Value fro timeformat '' is invalid. &lt;/H2&gt;

&lt;P&gt;04-11-2020 03:13:55.944 +0200 INFO TailReader -Batch input finished reading file='/opt/splunk/var/spool/splunk/1586567405_3259.stash_common_action_model' etc...&lt;BR /&gt;
NB:&lt;BR /&gt;
-here the problem is i don't know exactly what unknown error should i find to check ,here i find so many log information which i don't well understood,is there any known log error you know i could check on this ??what i was find i mentioned above seeing WARN and INFO,&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;3-command:systemctl status Splunkd if it is a systemd-enabled splunk&lt;/P&gt;

&lt;P&gt;running this ,even if splunkd is not running (./splunkd status) but using this command(systemctl ....) is showing me the below information:&lt;BR /&gt;
splunkd.service -Splunk service&lt;BR /&gt;
Loaded: loaded (/etc/systemd/system/splunkd.service;enabled;vendor preset: disabled)&lt;BR /&gt;
Active: active (running) since Sat 2020-04-18 02:14:21 CAT; 5 days ago&lt;BR /&gt;
process: 73xxx ExecStartPost=/bin/bash -c  chown -R ....etc&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;run grep -i splunk /var/log/messages&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Apr 23 20:10:01 splunksh systemd: Started Session 1065 of user root.&lt;BR /&gt;
Apr 23 19:50:01 Splunksh systemd: Removed Slice User  Slice of root.&lt;BR /&gt;
Apr 23 20:37:35 Splunksh systemd-logind: New Session 1071of user root.&lt;BR /&gt;
etc.... but the same as above&lt;/P&gt;

&lt;P&gt;May you identify the error on the above information? for me to be honest i don't well understood on how to fetch error/investigate this info and find error and fix it????&lt;BR /&gt;
I need help??&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 05:08:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-fix-failed-indexer-on-Splunkd/m-p/482489#M3985</guid>
      <dc:creator>pacifikn</dc:creator>
      <dc:date>2020-09-30T05:08:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix failed indexer on Splunkd?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-fix-failed-indexer-on-Splunkd/m-p/482490#M3986</link>
      <description>&lt;P&gt;Post the output of&lt;BR /&gt;
    ps aux | grep -i splunk&lt;/P&gt;

&lt;P&gt;It seems splunk is running&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2020 21:44:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-fix-failed-indexer-on-Splunkd/m-p/482490#M3986</guid>
      <dc:creator>PavelP</dc:creator>
      <dc:date>2020-04-23T21:44:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix failed indexer on Splunkd?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-fix-failed-indexer-on-Splunkd/m-p/482491#M3987</link>
      <description>&lt;P&gt;Dear PaveIP,&lt;BR /&gt;
the is the output of the command is:&lt;/P&gt;

&lt;H1&gt;ps aux |grep -i splunk&lt;/H1&gt;

&lt;P&gt;splunk    103..  0.4  0.1 3537.. 1047.. ?       Ssl  Apr17  39:16 splunkd --under-systemd --systemd-delegate=no -p 8189 _internal_launch_under_systemd&lt;BR /&gt;
splunk    107..  0.0  0.0      0     0 ?        Z    Apr17   0:00 [systemctl] &lt;BR /&gt;
splunk    108..  0.0  0.0  814..  95.. ?        Ss   Apr17   0:35 [splunkd pid=103..] splunkd --under-systemd --systemd-delegate=no -p 8189 _internal_launch_under_systemd [process-runner]&lt;BR /&gt;
root     1492..  0.0  0.0 1127..   996 pts/1    S+   06:21   0:00 grep --color=auto -i splunk&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 05:08:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-fix-failed-indexer-on-Splunkd/m-p/482491#M3987</guid>
      <dc:creator>pacifikn</dc:creator>
      <dc:date>2020-09-30T05:08:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to fix failed indexer on Splunkd?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-fix-failed-indexer-on-Splunkd/m-p/482492#M3988</link>
      <description>&lt;P&gt;yes, Splunk is running, I'd expect more processes. Can you post it again, with less editing using "code sample" button? And again the output of "systemctl status Splunkd". And don't remove important parts, it is all hidden behind "..."&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2020 05:44:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-fix-failed-indexer-on-Splunkd/m-p/482492#M3988</guid>
      <dc:creator>PavelP</dc:creator>
      <dc:date>2020-04-24T05:44:12Z</dc:date>
    </item>
  </channel>
</rss>

