<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Intermittent Unclean Shutdowns in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Intermittent-Unclean-Shutdowns/m-p/75756#M181403</link>
    <description>&lt;P&gt;After removing the "blockSignSize = 100" setting from the index, alerts on restart disappeared completely.&lt;/P&gt;

&lt;P&gt;Unsure if that's the right answer, but it seems to handle my issue at this time. Will continue to research and look for any future alerts from the system.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Apr 2011 03:02:35 GMT</pubDate>
    <dc:creator>tgiles</dc:creator>
    <dc:date>2011-04-12T03:02:35Z</dc:date>
    <item>
      <title>Intermittent Unclean Shutdowns</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Intermittent-Unclean-Shutdowns/m-p/75753#M181400</link>
      <description>&lt;P&gt;Hi, All.&lt;/P&gt;

&lt;P&gt;I'm setting up a new indexer and have run into an intermittent issue with Splunk (on 64 bit Linux) reporting an unclean shutdown and requiring to clean up before starting. It's happened the past 3 of the last 5 restarts I've done.&lt;/P&gt;

&lt;P&gt;System is currently just reading its own system logs into a separate index from main.&lt;/P&gt;

&lt;P&gt;(one shutdown)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;bucket=/opt/splunk/var/lib/splunk/audit/db/hot_v1_0 count mismatch tsidx=1401 source-metadata=1398, repairing...
bucket=/opt/splunk/var/lib/splunk/_internaldb/db/hot_v1_0 count mismatch tsidx=4021 source-metadata=3991, repairing...
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;(another shutdown)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;bucket=/opt/splunk/var/lib/splunk/audit/db/hot_v1_1 count mismatch tsidx=18 source-metadata=15, repairing...
bucket=/opt/splunk/var/lib/splunk/blockSignature/db/hot_v1_1 count mismatch tsidx=77 source-metadata=72, repairing...
bucket=/opt/splunk/var/lib/splunk/_internaldb/db/hot_v1_1 count mismatch tsidx=1800 source-metadata=1701, repairing...
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Questions I have is:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;P&gt;Is this to be expected in 4.2? I had 4.1 on some testing devices and never run into a problem with unclean shutdowns, even though it was restarted dozens of times.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;When it detects an unclean shutdown, /etc/init.d/splunk is useless- the system requires manual intervention. Is there a way to have Splunk automatically recover when it detects an unclean shutdown?&lt;/P&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Thanks in advance for your input!&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2011 22:34:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Intermittent-Unclean-Shutdowns/m-p/75753#M181400</guid>
      <dc:creator>tgiles</dc:creator>
      <dc:date>2011-04-06T22:34:53Z</dc:date>
    </item>
    <item>
      <title>Re: Intermittent Unclean Shutdowns</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Intermittent-Unclean-Shutdowns/m-p/75754#M181401</link>
      <description>&lt;P&gt;As a quick update- performing a full memory test on the system over the weekend to see if that might pin down the problem. Will update once I know more. Cheers&lt;/P&gt;</description>
      <pubDate>Sat, 09 Apr 2011 04:31:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Intermittent-Unclean-Shutdowns/m-p/75754#M181401</guid>
      <dc:creator>tgiles</dc:creator>
      <dc:date>2011-04-09T04:31:32Z</dc:date>
    </item>
    <item>
      <title>Re: Intermittent Unclean Shutdowns</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Intermittent-Unclean-Shutdowns/m-p/75755#M181402</link>
      <description>&lt;P&gt;No memory or hard drive issues with the target system. I tested a second indexer, restarted splunk a few times, and it came up with a "Splunk has detected an unclean shutdown." message as well.&lt;/P&gt;

&lt;P&gt;Note, this is different from SPL-37510. I'm not restarting it, going from a cold stop.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2011 21:03:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Intermittent-Unclean-Shutdowns/m-p/75755#M181402</guid>
      <dc:creator>tgiles</dc:creator>
      <dc:date>2011-04-11T21:03:24Z</dc:date>
    </item>
    <item>
      <title>Re: Intermittent Unclean Shutdowns</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Intermittent-Unclean-Shutdowns/m-p/75756#M181403</link>
      <description>&lt;P&gt;After removing the "blockSignSize = 100" setting from the index, alerts on restart disappeared completely.&lt;/P&gt;

&lt;P&gt;Unsure if that's the right answer, but it seems to handle my issue at this time. Will continue to research and look for any future alerts from the system.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2011 03:02:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Intermittent-Unclean-Shutdowns/m-p/75756#M181403</guid>
      <dc:creator>tgiles</dc:creator>
      <dc:date>2011-04-12T03:02:35Z</dc:date>
    </item>
    <item>
      <title>Re: Intermittent Unclean Shutdowns</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Intermittent-Unclean-Shutdowns/m-p/75757#M181404</link>
      <description>&lt;P&gt;Did this resolve your issue in the long term, and/or did you ever get any additional information?&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2011 18:11:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Intermittent-Unclean-Shutdowns/m-p/75757#M181404</guid>
      <dc:creator>southeringtonp</dc:creator>
      <dc:date>2011-05-04T18:11:55Z</dc:date>
    </item>
  </channel>
</rss>

