<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Error in search: Configuration initialization for /opt/splunk/etc in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Error-in-search-Configuration-initialization-for-opt-splunk-etc/m-p/508342#M142043</link>
    <description>&lt;P&gt;But finally how do I solve this problem?&lt;/P&gt;</description>
    <pubDate>Thu, 09 Jul 2020 16:26:44 GMT</pubDate>
    <dc:creator>rmanrique</dc:creator>
    <dc:date>2020-07-09T16:26:44Z</dc:date>
    <item>
      <title>Error in search: Configuration initialization for /opt/splunk/etc</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Error-in-search-Configuration-initialization-for-opt-splunk-etc/m-p/338326#M100342</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;I have an issue with about a searching, someone know about it, this is the issue: &lt;/P&gt;

&lt;P&gt;Error in search: "Configuration initialization for /opt/splunk/etc took longer than expected (XXX ms) when dispatching a search (ID) this typically reflects underlying storage performance issues"&lt;/P&gt;</description>
      <pubDate>Fri, 09 Mar 2018 23:09:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Error-in-search-Configuration-initialization-for-opt-splunk-etc/m-p/338326#M100342</guid>
      <dc:creator>Said7</dc:creator>
      <dc:date>2018-03-09T23:09:45Z</dc:date>
    </item>
    <item>
      <title>Re: Error in search: Configuration initialization for /opt/splunk/etc</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Error-in-search-Configuration-initialization-for-opt-splunk-etc/m-p/338327#M100343</link>
      <description>&lt;P&gt;This typically happens when search processes take time to read initial configuration information from disk. Did you check the utilization numbers on your server? Do you have sufficient system resources available? Did splunk start cleanly without any warnings or errors?&lt;/P&gt;</description>
      <pubDate>Sat, 10 Mar 2018 00:49:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Error-in-search-Configuration-initialization-for-opt-splunk-etc/m-p/338327#M100343</guid>
      <dc:creator>strive</dc:creator>
      <dc:date>2018-03-10T00:49:36Z</dc:date>
    </item>
    <item>
      <title>Re: Error in search: Configuration initialization for /opt/splunk/etc</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Error-in-search-Configuration-initialization-for-opt-splunk-etc/m-p/338328#M100344</link>
      <description>&lt;P&gt;Hey Said7,&lt;/P&gt;

&lt;P&gt;This message means your search processes are taking much time to read initial configuration information from disk. What does the I/O subsystem underneath $SPLUNK_HOME/etc look like in your environment? If $SPLUNK_HOME/etc is networked storage, for example, there might be disk/network performance issues affecting search startup time.&lt;/P&gt;

&lt;P&gt;Let me know if this helps!!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 18:27:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Error-in-search-Configuration-initialization-for-opt-splunk-etc/m-p/338328#M100344</guid>
      <dc:creator>deepashri_123</dc:creator>
      <dc:date>2020-09-29T18:27:57Z</dc:date>
    </item>
    <item>
      <title>Re: Error in search: Configuration initialization for /opt/splunk/etc</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Error-in-search-Configuration-initialization-for-opt-splunk-etc/m-p/338329#M100345</link>
      <description>&lt;P&gt;When you create a search, it creates a "search bundle" that contains all the knowledge objects associated with that search (lookups, etc.).&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;/opt/splunk/etc&lt;/CODE&gt; should have been populated with a file system path to the bundle.&lt;/P&gt;

&lt;P&gt;My guess is you have bad file system permissions and need to recursively chown your splunk directory and insure the proper user is running splunk.&lt;BR /&gt;
have a look at this &lt;A href="https://answers.splunk.com/answers/334789/why-am-i-getting-error-configuration-initializatio.html"&gt;accepted answer&lt;/A&gt;&lt;BR /&gt;
let me know if this helps!&lt;/P&gt;</description>
      <pubDate>Sat, 10 Mar 2018 05:43:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Error-in-search-Configuration-initialization-for-opt-splunk-etc/m-p/338329#M100345</guid>
      <dc:creator>mayurr98</dc:creator>
      <dc:date>2018-03-10T05:43:58Z</dc:date>
    </item>
    <item>
      <title>Re: Error in search: Configuration initialization for /opt/splunk/etc</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Error-in-search-Configuration-initialization-for-opt-splunk-etc/m-p/338330#M100346</link>
      <description>&lt;P&gt;how to resolve this issue ...facing same problem&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jan 2019 13:34:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Error-in-search-Configuration-initialization-for-opt-splunk-etc/m-p/338330#M100346</guid>
      <dc:creator>snigdha9nov</dc:creator>
      <dc:date>2019-01-25T13:34:59Z</dc:date>
    </item>
    <item>
      <title>Re: Error in search: Configuration initialization for /opt/splunk/etc</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Error-in-search-Configuration-initialization-for-opt-splunk-etc/m-p/508342#M142043</link>
      <description>&lt;P&gt;But finally how do I solve this problem?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2020 16:26:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Error-in-search-Configuration-initialization-for-opt-splunk-etc/m-p/508342#M142043</guid>
      <dc:creator>rmanrique</dc:creator>
      <dc:date>2020-07-09T16:26:44Z</dc:date>
    </item>
    <item>
      <title>Re: Error in search: Configuration initialization for /opt/splunk/etc</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Error-in-search-Configuration-initialization-for-opt-splunk-etc/m-p/619216#M215210</link>
      <description>&lt;P&gt;This message suggests there may be storage performance issues for the path mentioned on the Search Head. You may want to check the SH disk await times (ms) with the search below for the mount point where $SPLUNK_HOME &amp;nbsp;is mounted. Below 10ms is generally considered good performance. If you are seeing await times much higher you should confirm if the mount is NVME and if not, look to move the SH $SPLUNK_HOME mount to NVME for better performance (this is where bundles, search artifacts etc are stored).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| tstats
    max(data.avg_total_ms) as avg_total_ms
   where component::iostats sourcetype=splunk_resource_usage index=_introspection host IN ("*SH1*")
    by host
    data.mount_point
    _time
    span=60s |  timechart span=60s max(avg_total_ms) by data.mount_point | eval ideal_latency=10&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Some options for looking further into disk performance issues:&lt;/P&gt;&lt;P&gt;The &lt;STRONG&gt;iostat&lt;/STRONG&gt; command is used for monitoring system input/output device loading by observing the time the devices are active in relation to their average transfer rates.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;iostat -t -x 2 1800 &amp;gt;&amp;gt; /tmp/iostats.txt&lt;/LI-CODE&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Iotop is &lt;STRONG&gt;an open source and free utility similar to top command&lt;/STRONG&gt;, that provides an easy way to monitor Linux Disk I/O usage details and prints a table of existing I/O utilization by process or threads on the systems.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;iotop -botqqq --iter=1800 &amp;gt;&amp;gt; /tmp/iotop.log&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Nov 2022 23:55:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Error-in-search-Configuration-initialization-for-opt-splunk-etc/m-p/619216#M215210</guid>
      <dc:creator>rphillips_splk</dc:creator>
      <dc:date>2022-11-01T23:55:10Z</dc:date>
    </item>
    <item>
      <title>Re: Error in search: Configuration initialization for /opt/splunk/etc</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Error-in-search-Configuration-initialization-for-opt-splunk-etc/m-p/619217#M215211</link>
      <description>&lt;P&gt;&lt;SPAN&gt;you will need to install the following packages for the above commands&lt;BR /&gt;&lt;BR /&gt;yum install iotop -y&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;yum install sysstat -y&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Nov 2022 23:59:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Error-in-search-Configuration-initialization-for-opt-splunk-etc/m-p/619217#M215211</guid>
      <dc:creator>rphillips_splk</dc:creator>
      <dc:date>2022-11-01T23:59:59Z</dc:date>
    </item>
  </channel>
</rss>

