<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Rawdata may be corrupt in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Rawdata-may-be-corrupt/m-p/56745#M179889</link>
    <description>&lt;P&gt;Hi anyone and everyone,&lt;/P&gt;

&lt;P&gt;Please could somebody help.&lt;/P&gt;

&lt;P&gt;I have been using Splunk for the past 2 and a half years.&lt;BR /&gt;
I am using Splunk 5 and whenever I install a Splunk update over the existing Splunk 5, Splunk starts up as normal but after I perform a search, all the data will show until it gets to a point where it all vanishes and is replaced by the following.&lt;/P&gt;

&lt;P&gt;Error in 'databasePartitionPolicy': Failed to read 1 event(s) from rawdata in bucket 'main~178~02C5891B-D87B-444E-9AEC-E9C8E3E45913'. Rawdata may be corrupt, see search.log&lt;/P&gt;

&lt;P&gt;At this point I just reinstall the previous version as I need the search data.&lt;/P&gt;

&lt;P&gt;As I know I am going to have to update it for good at some point can any one fix this corruption issue?&lt;/P&gt;

&lt;P&gt;Kind regards,&lt;/P&gt;

&lt;P&gt;Paul&lt;/P&gt;</description>
    <pubDate>Thu, 06 Jun 2013 05:53:46 GMT</pubDate>
    <dc:creator>profileaudio</dc:creator>
    <dc:date>2013-06-06T05:53:46Z</dc:date>
    <item>
      <title>Rawdata may be corrupt</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Rawdata-may-be-corrupt/m-p/56745#M179889</link>
      <description>&lt;P&gt;Hi anyone and everyone,&lt;/P&gt;

&lt;P&gt;Please could somebody help.&lt;/P&gt;

&lt;P&gt;I have been using Splunk for the past 2 and a half years.&lt;BR /&gt;
I am using Splunk 5 and whenever I install a Splunk update over the existing Splunk 5, Splunk starts up as normal but after I perform a search, all the data will show until it gets to a point where it all vanishes and is replaced by the following.&lt;/P&gt;

&lt;P&gt;Error in 'databasePartitionPolicy': Failed to read 1 event(s) from rawdata in bucket 'main~178~02C5891B-D87B-444E-9AEC-E9C8E3E45913'. Rawdata may be corrupt, see search.log&lt;/P&gt;

&lt;P&gt;At this point I just reinstall the previous version as I need the search data.&lt;/P&gt;

&lt;P&gt;As I know I am going to have to update it for good at some point can any one fix this corruption issue?&lt;/P&gt;

&lt;P&gt;Kind regards,&lt;/P&gt;

&lt;P&gt;Paul&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2013 05:53:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Rawdata-may-be-corrupt/m-p/56745#M179889</guid>
      <dc:creator>profileaudio</dc:creator>
      <dc:date>2013-06-06T05:53:46Z</dc:date>
    </item>
    <item>
      <title>Re: Rawdata may be corrupt</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Rawdata-may-be-corrupt/m-p/56746#M179890</link>
      <description>&lt;P&gt;I have this same problem. Any answers?&lt;/P&gt;

&lt;P&gt;Updated answer:&lt;/P&gt;

&lt;P&gt;Without a service contract it is very difficult to get answers or a solution to this problem that dont include some data loss.&lt;/P&gt;

&lt;P&gt;Ultimately, I had to track down the data buckets that had the corrupt data and remove them. Some of my SOS data is also corrupted and i never have gotten around to sorting out which data needs to be gone.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2013 05:13:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Rawdata-may-be-corrupt/m-p/56746#M179890</guid>
      <dc:creator>asmithe</dc:creator>
      <dc:date>2013-12-03T05:13:03Z</dc:date>
    </item>
    <item>
      <title>Re: Rawdata may be corrupt</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Rawdata-may-be-corrupt/m-p/56747#M179891</link>
      <description>&lt;P&gt;I've run into this before also, and there is a fix IF the actual data in the bucket is not corrupt.  If the bucket raw data is truly corrupt, it cannot be fixed.&lt;/P&gt;

&lt;P&gt;Here is a good place to read about fixing bad buckets:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://wiki.splunk.com/Community:PostCrashFsckRepair"&gt;http://wiki.splunk.com/Community:PostCrashFsckRepair&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;The repair routine never worked for me, so I use the rebuild instructions.  However, sometimes those also fail for me, so modify the instructions a bit...&lt;/P&gt;

&lt;P&gt;First try the instructions as written.  If that fails try this on a copy of the bucket.&lt;/P&gt;

&lt;P&gt;Remove all files inside the bucket except &lt;CODE&gt;journal.gz&lt;/CODE&gt; - don't change the folder structure.  Run rebuild on the bucket again, and it will be rebuilt from raw data.  If that fails, then the data is likely unrecoverable.  &lt;/P&gt;</description>
      <pubDate>Sun, 09 Feb 2014 18:51:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Rawdata-may-be-corrupt/m-p/56747#M179891</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2014-02-09T18:51:19Z</dc:date>
    </item>
    <item>
      <title>Re: Rawdata may be corrupt</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Rawdata-may-be-corrupt/m-p/56748#M179892</link>
      <description>&lt;P&gt;I have this same problem. Any answers?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jul 2018 06:35:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Rawdata-may-be-corrupt/m-p/56748#M179892</guid>
      <dc:creator>khyoung7410</dc:creator>
      <dc:date>2018-07-09T06:35:36Z</dc:date>
    </item>
  </channel>
</rss>

