<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk 7.2 searches do not work after install. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-7-2-searches-do-not-work-after-install/m-p/451292#M127804</link>
    <description>&lt;P&gt;(And I know it looks like there's a disk space problem, but I provisioned 70GB on disk 1 and 500GB on disk 2 of my VM, and there's nothing else on the server besides the clean Splunk instance I just installed, so I'm not sure how that is contributing)&lt;/P&gt;</description>
    <pubDate>Wed, 31 Oct 2018 22:24:27 GMT</pubDate>
    <dc:creator>nick405060</dc:creator>
    <dc:date>2018-10-31T22:24:27Z</dc:date>
    <item>
      <title>Splunk 7.2 searches do not work after install.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-7-2-searches-do-not-work-after-install/m-p/451287#M127799</link>
      <description>&lt;P&gt;I can't run a search on either the Splunk 7.2 indexer or search head that I just installed. I get the error "Could not create search." I have no idea how to proceed and there is zero real documentation about this extremely fundamental error (I tried messing with limits.conf).&lt;/P&gt;

&lt;P&gt;I haven't done much configuration-wise so basically Splunk 7.2 gives this error - at least on a clean Ubuntu 16.04 VM - right out of the box. Fun times.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 19:38:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-7-2-searches-do-not-work-after-install/m-p/451287#M127799</guid>
      <dc:creator>nick405060</dc:creator>
      <dc:date>2018-10-31T19:38:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 7.2 searches do not work after install.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-7-2-searches-do-not-work-after-install/m-p/451288#M127800</link>
      <description>&lt;P&gt;@nick405060 , Do you see any error messages related to dispatcher? &lt;/P&gt;

&lt;P&gt;I used to see same error when all of our installation space occupied by a large search. As soon as we stop that search, we get back our space and then searches will run normally. &lt;/P&gt;

&lt;P&gt;Try to use default values in your limits.conf and give a restart.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Sandeep&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 20:42:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-7-2-searches-do-not-work-after-install/m-p/451288#M127800</guid>
      <dc:creator>sandeeprachuri</dc:creator>
      <dc:date>2018-10-31T20:42:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 7.2 searches do not work after install.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-7-2-searches-do-not-work-after-install/m-p/451289#M127801</link>
      <description>&lt;P&gt;I do have dispatch errors, however I haven't ran a large search yet (that I know of) and have rebooted Splunk a bunch of times. Dispatch folder is completely empty.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 21:04:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-7-2-searches-do-not-work-after-install/m-p/451289#M127801</guid>
      <dc:creator>nick405060</dc:creator>
      <dc:date>2018-10-31T21:04:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 7.2 searches do not work after install.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-7-2-searches-do-not-work-after-install/m-p/451290#M127802</link>
      <description>&lt;P&gt;@nick405060 , It's strange really. Can you post those errors?&lt;/P&gt;

&lt;P&gt;Also, make sure there are no special characters inserted in .conf files. Check recently changed .conf files. I usually press "CTRL + C/V/S" while doing changes in VI editor.&lt;BR /&gt;&lt;BR /&gt;
I had this issue sometime back, After the restart Splunk web was unavailable. It took sometime for me to figure out the error.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 21:50:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-7-2-searches-do-not-work-after-install/m-p/451290#M127802</guid>
      <dc:creator>sandeeprachuri</dc:creator>
      <dc:date>2018-10-31T21:50:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 7.2 searches do not work after install.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-7-2-searches-do-not-work-after-install/m-p/451291#M127803</link>
      <description>&lt;P&gt;Thanks a ton for helping me out. Replaced all conf files. Here are the current 7 messages Splunk gives me:&lt;/P&gt;

&lt;P&gt;Dispatch Command: The minimum free disk space (5000MB) reached for /opt/splunk/var/run/splunk/dispatch.&lt;BR /&gt;
10/31/2018, 3:19:00 PM&lt;BR /&gt;
Audit event generator: Now skipping indexing of internal audit events, because the downstream queue is not accepting data. Will keep dropping events until data flow resumes. Review system health: ensure downstream indexing and/or forwarding are operating correctly.&lt;BR /&gt;
10/31/2018, 3:15:18 PM&lt;BR /&gt;
Failed to start KV Store process. See mongod.log and splunkd.log for details.&lt;BR /&gt;
10/31/2018, 12:23:33 PM&lt;BR /&gt;
Splunk has found 34 orphaned searches owned by 1 unique disabled users.Click to view the orphaned scheduled searches. Reassign them to a valid user to re-enable or alternatively disable the searches.&lt;BR /&gt;
10/31/2018, 12:23:33 PM&lt;BR /&gt;
Disk Monitor: The index processor has paused data flow. Current free disk space on partition '/' has fallen to 4297MB, below the minimum of 5000MB. Data writes to index path '/opt/splunk/var/lib/splunk/audit/db'cannot safely proceed. Increase free disk space on partition '/' by removing or relocating data. Learn more.&lt;BR /&gt;
10/31/2018, 12:23:32 PM&lt;BR /&gt;
KV Store changed status to failed. KVStore process terminated.&lt;BR /&gt;
10/31/2018, 12:23:32 PM&lt;BR /&gt;
KV Store process terminated abnormally (exit code 1, status exited with code 1). See mongod.log and splunkd.log for details.&lt;BR /&gt;
10/31/2018, 12:23:32 PM&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 22:20:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-7-2-searches-do-not-work-after-install/m-p/451291#M127803</guid>
      <dc:creator>nick405060</dc:creator>
      <dc:date>2018-10-31T22:20:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 7.2 searches do not work after install.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-7-2-searches-do-not-work-after-install/m-p/451292#M127804</link>
      <description>&lt;P&gt;(And I know it looks like there's a disk space problem, but I provisioned 70GB on disk 1 and 500GB on disk 2 of my VM, and there's nothing else on the server besides the clean Splunk instance I just installed, so I'm not sure how that is contributing)&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 22:24:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-7-2-searches-do-not-work-after-install/m-p/451292#M127804</guid>
      <dc:creator>nick405060</dc:creator>
      <dc:date>2018-10-31T22:24:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 7.2 searches do not work after install.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-7-2-searches-do-not-work-after-install/m-p/451293#M127805</link>
      <description>&lt;P&gt;fdisk -l:&lt;/P&gt;

&lt;P&gt;Disk /dev/sda: 70 GiB, 75161927680 bytes, 146800640 sectors&lt;BR /&gt;
Units: sectors of 1 * 512 = 512 bytes&lt;BR /&gt;
Sector size (logical/physical): 512 bytes / 512 bytes&lt;BR /&gt;
I/O size (minimum/optimal): 512 bytes / 512 bytes&lt;BR /&gt;
Disklabel type: dos&lt;BR /&gt;
Disk identifier: 0xc1cc14d8&lt;/P&gt;

&lt;P&gt;Device     Boot   Start       End   Sectors  Size Id Type&lt;BR /&gt;
/dev/sda1  *       2048   1499135   1497088  731M 83 Linux&lt;BR /&gt;
/dev/sda2       1501182 146798591 145297410 69.3G  5 Extended&lt;BR /&gt;
/dev/sda5       1501184 146798591 145297408 69.3G 8e Linux LVM&lt;/P&gt;

&lt;P&gt;Disk /dev/sdb: 500 GiB, 536870912000 bytes, 1048576000 sectors&lt;BR /&gt;
Units: sectors of 1 * 512 = 512 bytes&lt;BR /&gt;
Sector size (logical/physical): 512 bytes / 512 bytes&lt;BR /&gt;
I/O size (minimum/optimal): 512 bytes / 512 bytes&lt;/P&gt;

&lt;P&gt;Disk /dev/mapper/1ABC--ABC01--AB1--vg-root: 8.4 GiB, 8975810560 bytes, 17530880 sectors&lt;BR /&gt;
Units: sectors of 1 * 512 = 512 bytes&lt;BR /&gt;
Sector size (logical/physical): 512 bytes / 512 bytes&lt;BR /&gt;
I/O size (minimum/optimal): 512 bytes / 512 bytes&lt;/P&gt;

&lt;P&gt;Disk /dev/mapper/1SPL--INF01--DC1--vg-swap_1: 976 MiB, 1023410176 bytes, 1998848 sectors&lt;BR /&gt;
Units: sectors of 1 * 512 = 512 bytes&lt;BR /&gt;
Sector size (logical/physical): 512 bytes / 512 bytes&lt;BR /&gt;
I/O size (minimum/optimal): 512 bytes / 512 bytes&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 22:33:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-7-2-searches-do-not-work-after-install/m-p/451293#M127805</guid>
      <dc:creator>nick405060</dc:creator>
      <dc:date>2018-10-31T22:33:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 7.2 searches do not work after install.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-7-2-searches-do-not-work-after-install/m-p/451294#M127806</link>
      <description>&lt;P&gt;Resized my partitions and that fixed the problem.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 23:32:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-7-2-searches-do-not-work-after-install/m-p/451294#M127806</guid>
      <dc:creator>nick405060</dc:creator>
      <dc:date>2018-10-31T23:32:33Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 7.2 searches do not work after install.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-7-2-searches-do-not-work-after-install/m-p/451295#M127807</link>
      <description>&lt;P&gt;I can see that minimum disk space is fallen below 5000MB. This will stop searches. As a workaround, change that to 1000 or 500MB and give a restart. I used to do this every time. Once our /OPT folder increased to 60GB from 6GB, I changed back the setting to 5000MB.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 23:32:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-7-2-searches-do-not-work-after-install/m-p/451295#M127807</guid>
      <dc:creator>sandeeprachuri</dc:creator>
      <dc:date>2018-10-31T23:32:34Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 7.2 searches do not work after install.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-7-2-searches-do-not-work-after-install/m-p/451296#M127808</link>
      <description>&lt;P&gt;Can a moderator move this comment to be an answer? Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2018 23:34:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-7-2-searches-do-not-work-after-install/m-p/451296#M127808</guid>
      <dc:creator>nick405060</dc:creator>
      <dc:date>2018-10-31T23:34:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 7.2 searches do not work after install.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-7-2-searches-do-not-work-after-install/m-p/451297#M127809</link>
      <description>&lt;P&gt;@nick405060 added as a answer&lt;/P&gt;

&lt;P&gt;I can see that minimum disk space is fallen below 5000MB. This will stop searches. As a workaround, change that to 1000 or 500MB and give a restart. I used to do this every time. Once our /OPT folder increased to 60GB from 6GB, I changed back the setting to 5000MB.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Nov 2018 05:53:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-7-2-searches-do-not-work-after-install/m-p/451297#M127809</guid>
      <dc:creator>sandeeprachuri</dc:creator>
      <dc:date>2018-11-01T05:53:29Z</dc:date>
    </item>
  </channel>
</rss>

