<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Errors in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Errors/m-p/43757#M10303</link>
    <description>&lt;P&gt;Hi, I am getting this error when I open one of my dashboards today.&lt;/P&gt;

&lt;P&gt;" Error in 'databasePartitionPolicy': Failed to read 1 event(s) from rawdata in bucket 'main-xxxxxx'. Rawdata may be corrupt, see search.log."&lt;/P&gt;

&lt;P&gt;this is what i see in search.log&lt;/P&gt;

&lt;P&gt;02-26-2013 11:22:21.540 INFO  DispatchCommand - Round Robin Threaded ProviderQueue: done reading from peer 'BP1LCSAP031'&lt;BR /&gt;
02-26-2013 11:22:23.506 ERROR JournalSlice - Cannot seek to 74529344&lt;BR /&gt;
02-26-2013 11:22:23.506 ERROR databasePartitionPolicy - Failed to read event at address=2329042 in rawdata directory: \reuxeuss019-f07\splunk_index\defaultdb\db\db_1361833650_1361568580_55\rawdata&lt;BR /&gt;
02-26-2013 11:22:23.506 ERROR databasePartitionPolicy - Failed to read 1 event(s) from rawdata in bucket 'main~55~004CC9C7-AEAA-4C5A-B3C7-2B22F4A91F7D'. Rawdata may be corrupt, see search.log&lt;BR /&gt;
02-26-2013 11:22:23.521 INFO  IndexScopedSearch - PREAD_HISTOGRAM: usec_1_8=3718 usec_8_64=0 usec_64_512=0 usec_512_4096=0 usec_4096_32768=9 &lt;/P&gt;

&lt;P&gt;Any suggestions please?&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 13:23:34 GMT</pubDate>
    <dc:creator>sriva6</dc:creator>
    <dc:date>2020-09-28T13:23:34Z</dc:date>
    <item>
      <title>Splunk Errors</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Errors/m-p/43757#M10303</link>
      <description>&lt;P&gt;Hi, I am getting this error when I open one of my dashboards today.&lt;/P&gt;

&lt;P&gt;" Error in 'databasePartitionPolicy': Failed to read 1 event(s) from rawdata in bucket 'main-xxxxxx'. Rawdata may be corrupt, see search.log."&lt;/P&gt;

&lt;P&gt;this is what i see in search.log&lt;/P&gt;

&lt;P&gt;02-26-2013 11:22:21.540 INFO  DispatchCommand - Round Robin Threaded ProviderQueue: done reading from peer 'BP1LCSAP031'&lt;BR /&gt;
02-26-2013 11:22:23.506 ERROR JournalSlice - Cannot seek to 74529344&lt;BR /&gt;
02-26-2013 11:22:23.506 ERROR databasePartitionPolicy - Failed to read event at address=2329042 in rawdata directory: \reuxeuss019-f07\splunk_index\defaultdb\db\db_1361833650_1361568580_55\rawdata&lt;BR /&gt;
02-26-2013 11:22:23.506 ERROR databasePartitionPolicy - Failed to read 1 event(s) from rawdata in bucket 'main~55~004CC9C7-AEAA-4C5A-B3C7-2B22F4A91F7D'. Rawdata may be corrupt, see search.log&lt;BR /&gt;
02-26-2013 11:22:23.521 INFO  IndexScopedSearch - PREAD_HISTOGRAM: usec_1_8=3718 usec_8_64=0 usec_64_512=0 usec_512_4096=0 usec_4096_32768=9 &lt;/P&gt;

&lt;P&gt;Any suggestions please?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:23:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Errors/m-p/43757#M10303</guid>
      <dc:creator>sriva6</dc:creator>
      <dc:date>2020-09-28T13:23:34Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Errors</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Errors/m-p/43758#M10304</link>
      <description>&lt;P&gt;tried a reboot of splunkd? this may rebuild corrupt sections.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2013 11:53:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Errors/m-p/43758#M10304</guid>
      <dc:creator>SplunkFu</dc:creator>
      <dc:date>2013-02-26T11:53:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Errors</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Errors/m-p/43759#M10305</link>
      <description>&lt;P&gt;No, I haven't tried a reboot yet but this was working fine till yesterday. Also, I see these as well in the indexing errors:&lt;/P&gt;

&lt;P&gt;INFO  databasePartitionPolicy - idx=_audit Moving from='hot_v1_48' to warm='write error on hot bucket'&lt;BR /&gt;
»  2/26/13&lt;BR /&gt;
11:46:04.961 AM &lt;BR /&gt;
02-26-2013 11:46:04.961 +0000 ERROR databasePartitionPolicy - Unable to write raw: for idx=_audit, path='\reuxeuss019-f07\splunk_index\audit\db\hot_v1_48'&lt;BR /&gt;
»  2/26/13&lt;BR /&gt;
11:45:26.989 AM &lt;BR /&gt;
02-26-2013 11:45:26.989 +0000 INFO  databasePartitionPolicy - idx=_internal Moving from='hot_v1_67' to warm='write error on hot bucket'&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:23:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Errors/m-p/43759#M10305</guid>
      <dc:creator>sriva6</dc:creator>
      <dc:date>2020-09-28T13:23:37Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Errors</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Errors/m-p/43760#M10306</link>
      <description>&lt;P&gt;You may need to manually run FSCK against your buckets, have a look here for the detail;&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Indexer/HowSplunkstoresindexes#Troubleshoot_your_buckets"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Indexer/HowSplunkstoresindexes#Troubleshoot_your_buckets&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Also, if you store your buckets on another filesystem/partition make sure that there are no issues with permissions or the user that Splunk is running as can access them still.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2013 12:38:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Errors/m-p/43760#M10306</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2013-02-26T12:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Errors</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Errors/m-p/43761#M10307</link>
      <description>&lt;P&gt;running FSCK helped&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2013 15:45:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Errors/m-p/43761#M10307</guid>
      <dc:creator>sriva6</dc:creator>
      <dc:date>2013-02-26T15:45:00Z</dc:date>
    </item>
  </channel>
</rss>

