<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to start splunk in Indexer in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Unable-to-start-splunk-in-Indexer/m-p/513505#M4407</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;Thanks for the info. I have checked file&amp;nbsp; permission&amp;nbsp; on other working indexers also, Its same only. Can you plz guide me how to find any corrupted data&lt;/P&gt;</description>
    <pubDate>Tue, 11 Aug 2020 06:39:20 GMT</pubDate>
    <dc:creator>BRG</dc:creator>
    <dc:date>2020-08-11T06:39:20Z</dc:date>
    <item>
      <title>Unable to start splunk in Indexer</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Unable-to-start-splunk-in-Indexer/m-p/513488#M4402</link>
      <description>&lt;P&gt;I am having indexer clusters&amp;nbsp; &amp;amp; one of the indexer goes down due to some reason, I am unable to start splunk in that server. Its giving me below error.&lt;/P&gt;&lt;DIV&gt;[root@ bin]# ./splunk start&lt;BR /&gt;splunkd 21888 was not running.&lt;BR /&gt;Stopping splunk helpers...&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;[ &amp;nbsp;OK &amp;nbsp;]&lt;BR /&gt;Done.&lt;BR /&gt;Stopped helpers.&lt;BR /&gt;Removing stale pid file... Can't unlink pid file "/opt/splunk/var/run/splunk/splunkd.pid": Read-only file system&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;splunk version is 6.4.2 .&lt;/DIV&gt;&lt;DIV&gt;kindly help me to start splunk service.&lt;/DIV&gt;</description>
      <pubDate>Tue, 11 Aug 2020 03:25:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Unable-to-start-splunk-in-Indexer/m-p/513488#M4402</guid>
      <dc:creator>BRG</dc:creator>
      <dc:date>2020-08-11T03:25:14Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to start splunk in Indexer</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Unable-to-start-splunk-in-Indexer/m-p/513491#M4403</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/224813"&gt;@BRG&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Looks like the splunk process is not able to read the file&amp;nbsp;&lt;SPAN&gt;/opt/splunk/var/run/splunk/splunkd.pid.&lt;BR /&gt;Remove the splunkd.pid file under the location&amp;nbsp;/opt/splunk/var/run/splunk and start again.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2020 03:53:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Unable-to-start-splunk-in-Indexer/m-p/513491#M4403</guid>
      <dc:creator>impurush</dc:creator>
      <dc:date>2020-08-11T03:53:48Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to start splunk in Indexer</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Unable-to-start-splunk-in-Indexer/m-p/513495#M4404</link>
      <description>&lt;DIV&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/44228"&gt;@impurush&lt;/a&gt;&amp;nbsp;Will this change impact the other nodes in Indexer cluster ? As this is in production setup.&lt;/DIV&gt;&lt;P&gt;Also version of splunk is old.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2020 04:46:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Unable-to-start-splunk-in-Indexer/m-p/513495#M4404</guid>
      <dc:creator>BRG</dc:creator>
      <dc:date>2020-08-11T04:46:29Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to start splunk in Indexer</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Unable-to-start-splunk-in-Indexer/m-p/513497#M4405</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/224813"&gt;@BRG&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;By seeing ur question,It looks like the splunk is already stopped. So when you are starting you are getting this error right.&lt;/P&gt;&lt;P&gt;Also, removing this file will not affect your cluster.&lt;/P&gt;&lt;P&gt;To be safer side, check the Child process id in the file is already running or not. If not, u can kill the process id and &amp;nbsp;remove the file, then start the splunk.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2020 04:56:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Unable-to-start-splunk-in-Indexer/m-p/513497#M4405</guid>
      <dc:creator>impurush</dc:creator>
      <dc:date>2020-08-11T04:56:04Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to start splunk in Indexer</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Unable-to-start-splunk-in-Indexer/m-p/513498#M4406</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;for reasons your file system has gone to read only mode. You must figure out why and then fix it by remounting it to rw-mode. After that you could star splunk as normal way. Then you must look are there any corrupted data or not.&amp;nbsp;&lt;BR /&gt;r. &amp;nbsp;Ismo&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2020 05:03:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Unable-to-start-splunk-in-Indexer/m-p/513498#M4406</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-08-11T05:03:07Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to start splunk in Indexer</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Unable-to-start-splunk-in-Indexer/m-p/513505#M4407</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;Thanks for the info. I have checked file&amp;nbsp; permission&amp;nbsp; on other working indexers also, Its same only. Can you plz guide me how to find any corrupted data&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2020 06:39:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Unable-to-start-splunk-in-Indexer/m-p/513505#M4407</guid>
      <dc:creator>BRG</dc:creator>
      <dc:date>2020-08-11T06:39:20Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to start splunk in Indexer</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Unable-to-start-splunk-in-Indexer/m-p/513506#M4408</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/44228"&gt;@impurush&lt;/a&gt;&amp;nbsp;Thanks for the info. file name conf-mutator.pid&amp;nbsp; have also same pid no. i.e 21888, do i have to remove this file also ?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2020 06:42:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Unable-to-start-splunk-in-Indexer/m-p/513506#M4408</guid>
      <dc:creator>BRG</dc:creator>
      <dc:date>2020-08-11T06:42:27Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to start splunk in Indexer</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Unable-to-start-splunk-in-Indexer/m-p/513507#M4409</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I'm afraid that there is no any easy way to find it. Probably best options is to look from MC (monitoring console) that there is no buckets in unsync status (RF or SF is not fulfil).&lt;/P&gt;&lt;P&gt;Also try to look from internal logs that there is no ERROR level events related to indexing.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2020 06:42:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Unable-to-start-splunk-in-Indexer/m-p/513507#M4409</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-08-11T06:42:42Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to start splunk in Indexer</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Unable-to-start-splunk-in-Indexer/m-p/513814#M4410</link>
      <description>&lt;P&gt;You're restarting splunkd using root, instead of Splunk. This usually causes such problems. Are all of your Indexers running as root?&lt;/P&gt;&lt;P&gt;I'd try to check the permissions of the files, get rid of the PID and restart splunk using the user which was used to install the software, in most cases, it's Splunk.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Aug 2020 22:08:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Unable-to-start-splunk-in-Indexer/m-p/513814#M4410</guid>
      <dc:creator>shivanshu1593</dc:creator>
      <dc:date>2020-08-12T22:08:05Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to start splunk in Indexer</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Unable-to-start-splunk-in-Indexer/m-p/513845#M4413</link>
      <description>&lt;P&gt;If you are running splunk under systemd instead of traditional/old way, you actually must start it as root using the commend "systemctl start splunk.service" (or what ever your unit-file/service name is). &amp;nbsp;If you want still start it as splunk (or what ever your splunk service account is) you must add separately some additional tasks / rights to that user.&lt;/P&gt;&lt;P&gt;But if you are using it old way, then manage all starts alway as that service user like splunk, otherwise you has issues as&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/61125"&gt;@shivanshu1593&lt;/a&gt;&amp;nbsp;mentioned. But in your case there has been some OS level issues as filesystem has changed to readonly mode. And root cause for this is something which must figure first and then all other steps.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.5/Admin/ConfigureSplunktostartatboottime" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.5/Admin/ConfigureSplunktostartatboottime&lt;/A&gt;&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2020 08:14:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Unable-to-start-splunk-in-Indexer/m-p/513845#M4413</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-08-13T08:14:33Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to start splunk in Indexer</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Unable-to-start-splunk-in-Indexer/m-p/520058#M4455</link>
      <description>&lt;P&gt;Sorry for the late reply,&lt;/P&gt;&lt;P&gt;Even though i tried to remove the file but its giving me error of Read-only file system.&lt;/P&gt;&lt;DIV&gt;&lt;FONT size="3"&gt;rm: cannot remove `splunkd.pid': Read-only file system&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT size="3"&gt;Also moving file to another location is also not working.&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT size="3"&gt;Can we have any other option?&lt;/FONT&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 17 Sep 2020 07:00:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Unable-to-start-splunk-in-Indexer/m-p/520058#M4455</guid>
      <dc:creator>BRG</dc:creator>
      <dc:date>2020-09-17T07:00:18Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to start splunk in Indexer</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Unable-to-start-splunk-in-Indexer/m-p/520081#M4456</link>
      <description>You must solve the reason why this file system has changed to read-only, fix it and there you must remount it to read write or even reboot the system and after that you can try to restart splunk, not earlier than fs is remounted to rw mode.&lt;BR /&gt;r. Ismo</description>
      <pubDate>Thu, 17 Sep 2020 08:41:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Unable-to-start-splunk-in-Indexer/m-p/520081#M4456</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-09-17T08:41:46Z</dc:date>
    </item>
  </channel>
</rss>

