<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk unable to start and emits &amp;quot;Conf is currently being modified by process ####.&amp;quot; in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-unable-to-start-and-emits-quot-Conf-is-currently-being/m-p/101529#M182863</link>
    <description>&lt;P&gt;If splunk run as root it's normal that the file is owned by root, but I expect the file to be deleted after a clean stop.&lt;BR /&gt;
Maybe the process crashed too quickly or a lock stayed  on the file.&lt;/P&gt;

&lt;P&gt;Double check under which user splunk is running, and check /var/log/messages to see if the process was not killed by the system for OOM.&lt;/P&gt;</description>
    <pubDate>Tue, 29 Jan 2013 01:11:55 GMT</pubDate>
    <dc:creator>yannK</dc:creator>
    <dc:date>2013-01-29T01:11:55Z</dc:date>
    <item>
      <title>Splunk unable to start and emits "Conf is currently being modified by process ####."</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-unable-to-start-and-emits-quot-Conf-is-currently-being/m-p/101521#M182855</link>
      <description>&lt;P&gt;This morning after rebooting my computer with splunk on it, Splunk refuses to start.&lt;/P&gt;

&lt;P&gt;Trying to investigate the problem, I found a few odd things. The most likely error is identified by a message [Conf is currently being modified by process 4432] which occurs on a number of attempts at starting splunk, or trying to check licence via cli, for instance.  The strange thing is that there does not seem to be a process 4432 running on my computer!&lt;/P&gt;

&lt;P&gt;Has Splunk got corrupted somehow?&lt;/P&gt;

&lt;P&gt;Here is an odd extract from the logs: &lt;BR /&gt;
01-28-2013 02:30:55.412 +0800 INFO  LicenseMgr - Initing LicenseMgr runContext_splunkd=false&lt;BR /&gt;
01-28-2013 02:30:55.412 +0800 INFO  LMStackMgr - closing stack mgr&lt;BR /&gt;
01-28-2013 02:30:55.412 +0800 INFO  LMSlaveInfo - all slaves cleared&lt;BR /&gt;
01-28-2013 02:30:55.422 +0800 INFO  LMStackMgr - created stack='download-trial'&lt;BR /&gt;
01-28-2013 02:30:55.422 +0800 INFO  LMStackMgr - have to auto-set active stack group='Trial' reason='invalid/missing group id' gidStr='' oldGid=Invalid&lt;/P&gt;

&lt;P&gt;I start splunk via the CLI as:&lt;/P&gt;

&lt;P&gt;"$ sudo /opt/splunk/bin/splunk start"&lt;/P&gt;

&lt;P&gt;I then get the following:&lt;/P&gt;

&lt;P&gt;"Splunk&amp;gt; Winning the War on Error&lt;/P&gt;

&lt;P&gt;Checking prerequisites...&lt;BR /&gt;
    Checking http port [8000]: open&lt;BR /&gt;
    Checking mgmt port [8089]: open&lt;BR /&gt;
    Checking configuration...  Done.&lt;BR /&gt;
    Checking indexes...&lt;BR /&gt;
        Validated databases: _audit _blocksignature _internal _thefishbucket history main os sos sos_summary_daily summary&lt;BR /&gt;
    Done&lt;BR /&gt;
    Checking filesystem compatibility...  Done&lt;BR /&gt;
    Checking conf files for typos...    Done&lt;BR /&gt;
All preliminary checks passed.&lt;/P&gt;

&lt;P&gt;Conf is currently being modified by process 4432.&lt;BR /&gt;
Conf is currently being modified by process 4432.&lt;BR /&gt;
Conf is currently being modified by process 4432.&lt;BR /&gt;
Conf is currently being modified by process 4432.&lt;BR /&gt;
Conf is currently being modified by process 4432.&lt;BR /&gt;
Conf is currently being modified by process 4432.&lt;BR /&gt;
Starting splunk server daemon (splunkd)...&lt;BR /&gt;&lt;BR /&gt;
Timed out waiting for splunkd to start.&lt;BR /&gt;
Starting splunkweb...  Done&lt;/P&gt;

&lt;P&gt;If you get stuck, we're here to help.&lt;BR /&gt;&lt;BR /&gt;
Look for answers here: &lt;A href="http://docs.splunk.com" target="_blank"&gt;http://docs.splunk.com&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;The Splunk web interface is at &lt;A href="http://wolfgang:8000" target="_blank"&gt;http://wolfgang:8000&lt;/A&gt;"&lt;/P&gt;

&lt;P&gt;and on attempting to reach splunk via the web interface, I get:&lt;/P&gt;

&lt;P&gt;"The splunkd daemon cannot be reached by splunkweb. Check that there are no blocked network ports or that splunkd is still running."&lt;/P&gt;

&lt;P&gt;With the following at the bottom of the screen:&lt;/P&gt;

&lt;P&gt;"You are using wolfgang:8000, which is connected to splunkd @000 at &lt;A href="https://127.0.0.1:8089" target="_blank"&gt;https://127.0.0.1:8089&lt;/A&gt; on Mon Jan 28 04:52:13 2013."&lt;/P&gt;

&lt;P&gt;The @000 seems a bit odd, no?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:11:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-unable-to-start-and-emits-quot-Conf-is-currently-being/m-p/101521#M182855</guid>
      <dc:creator>MidGe</dc:creator>
      <dc:date>2020-09-28T13:11:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk unable to start and emits "Conf is currently being modified by process ####."</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-unable-to-start-and-emits-quot-Conf-is-currently-being/m-p/101522#M182856</link>
      <description>&lt;P&gt;Sorry, just to be clear. What happens when you try to start Splunk and how are you starting Splunk?&lt;/P&gt;</description>
      <pubDate>Sun, 27 Jan 2013 20:36:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-unable-to-start-and-emits-quot-Conf-is-currently-being/m-p/101522#M182856</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2013-01-27T20:36:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk unable to start and emits "Conf is currently being modified by process ####."</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-unable-to-start-and-emits-quot-Conf-is-currently-being/m-p/101523#M182857</link>
      <description>&lt;P&gt;Thanks for your attention to this.&lt;/P&gt;

&lt;P&gt;I edited my original post as comment on your question did not allow enough characters.&lt;/P&gt;</description>
      <pubDate>Sun, 27 Jan 2013 21:01:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-unable-to-start-and-emits-quot-Conf-is-currently-being/m-p/101523#M182857</guid>
      <dc:creator>MidGe</dc:creator>
      <dc:date>2013-01-27T21:01:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk unable to start and emits "Conf is currently being modified by process ####."</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-unable-to-start-and-emits-quot-Conf-is-currently-being/m-p/101524#M182858</link>
      <description>&lt;P&gt;The @000 suggests that splunkweb isn't connected to splunkd, probably due to splunkd not having started.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jan 2013 08:26:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-unable-to-start-and-emits-quot-Conf-is-currently-being/m-p/101524#M182858</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2013-01-28T08:26:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk unable to start and emits "Conf is currently being modified by process ####."</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-unable-to-start-and-emits-quot-Conf-is-currently-being/m-p/101525#M182859</link>
      <description>&lt;P&gt;when you say that there is no process 4432 running, how are you checking for this?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jan 2013 08:56:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-unable-to-start-and-emits-quot-Conf-is-currently-being/m-p/101525#M182859</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2013-01-28T08:56:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk unable to start and emits "Conf is currently being modified by process ####."</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-unable-to-start-and-emits-quot-Conf-is-currently-being/m-p/101526#M182860</link>
      <description>&lt;P&gt;I checked that there was no process 4432 doing a "ps aux".&lt;/P&gt;

&lt;P&gt;Secondly, even after areboot it is still complaining about the same process 4432!  It seems to me that Splunk has a variable set to 4432 somewhere that is persistent between reboots and restarts.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jan 2013 11:36:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-unable-to-start-and-emits-quot-Conf-is-currently-being/m-p/101526#M182860</guid>
      <dc:creator>MidGe</dc:creator>
      <dc:date>2013-01-28T11:36:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk unable to start and emits "Conf is currently being modified by process ####."</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-unable-to-start-and-emits-quot-Conf-is-currently-being/m-p/101527#M182861</link>
      <description>&lt;P&gt;I wonder if you do not have some file owned by a different user than the one running splunk&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;1 stop splunk&lt;/LI&gt;
&lt;LI&gt;2 check the presence and owner/permissions on $SPLUNK_HOME/var/run/splunk/*.pid&lt;/LI&gt;
&lt;LI&gt;3 delete them if they still exists&lt;/LI&gt;
&lt;LI&gt;4 if needed do a chown -R for the splunk folders to change the owner&lt;/LI&gt;
&lt;LI&gt;5 start splunk under the correct user&lt;/LI&gt;
&lt;LI&gt;6 double check that the service starts with the correct user&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 28 Jan 2013 18:16:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-unable-to-start-and-emits-quot-Conf-is-currently-being/m-p/101527#M182861</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2013-01-28T18:16:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk unable to start and emits "Conf is currently being modified by process ####."</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-unable-to-start-and-emits-quot-Conf-is-currently-being/m-p/101528#M182862</link>
      <description>&lt;P&gt;Hiya yannK,&lt;/P&gt;

&lt;P&gt;Thanks for your reply. This fixed the problem.&lt;BR /&gt;
I only had to delete the *.pid file which was created around the time the problem started. That file contained a single line entry which was "4432".  That is the non-exixtent process that Splunk was complaining about and why it refused to start.&lt;/P&gt;

&lt;P&gt;BTW tat file was owned by root with root user having the only permissions on it.&lt;/P&gt;

&lt;P&gt;Now, to satisfy my curiosity and my paranoiac tendencies, what could be the cause of such behaviour?  Should I be concerned about a possible intrusion in my system?  Alternatively what can I do to mitigate the possibility of a recurrence?&lt;/P&gt;

&lt;P&gt;Thanks a lot for the answer that did solve my problem. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Jan 2013 01:01:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-unable-to-start-and-emits-quot-Conf-is-currently-being/m-p/101528#M182862</guid>
      <dc:creator>MidGe</dc:creator>
      <dc:date>2013-01-29T01:01:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk unable to start and emits "Conf is currently being modified by process ####."</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-unable-to-start-and-emits-quot-Conf-is-currently-being/m-p/101529#M182863</link>
      <description>&lt;P&gt;If splunk run as root it's normal that the file is owned by root, but I expect the file to be deleted after a clean stop.&lt;BR /&gt;
Maybe the process crashed too quickly or a lock stayed  on the file.&lt;/P&gt;

&lt;P&gt;Double check under which user splunk is running, and check /var/log/messages to see if the process was not killed by the system for OOM.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jan 2013 01:11:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-unable-to-start-and-emits-quot-Conf-is-currently-being/m-p/101529#M182863</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2013-01-29T01:11:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk unable to start and emits "Conf is currently being modified by process ####."</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-unable-to-start-and-emits-quot-Conf-is-currently-being/m-p/101530#M182864</link>
      <description>&lt;P&gt;in additional to yannK answer.&lt;/P&gt;

&lt;P&gt;remove the following pid files from $SPLUNK_HOME/var/run/splunk if they exist&lt;BR /&gt;
 - splunkd.pid.corrupt&lt;BR /&gt;
 - conf-mutator.pid&lt;/P&gt;

&lt;P&gt;and start splunk/splunkforwarder&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2013 22:27:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-unable-to-start-and-emits-quot-Conf-is-currently-being/m-p/101530#M182864</guid>
      <dc:creator>vvereschaka</dc:creator>
      <dc:date>2013-11-14T22:27:52Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk unable to start and emits "Conf is currently being modified by process ####."</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-unable-to-start-and-emits-quot-Conf-is-currently-being/m-p/101531#M182865</link>
      <description>&lt;P&gt;Very early in the life of conf-mutator.pid (5.x), the way the pid was tested would return true for any running THREAD.  In modern linux, threads and processes IDs live in the same number space, so you can accidentally find a thread depending how you are testing for processes.  You could have checked for a thread with &lt;CODE&gt;ps auxH&lt;/CODE&gt; because.. H means .. tHread? or something?&lt;/P&gt;</description>
      <pubDate>Sun, 05 Oct 2014 00:31:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-unable-to-start-and-emits-quot-Conf-is-currently-being/m-p/101531#M182865</guid>
      <dc:creator>jrodman</dc:creator>
      <dc:date>2014-10-05T00:31:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk unable to start and emits "Conf is currently being modified by process ####."</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-unable-to-start-and-emits-quot-Conf-is-currently-being/m-p/101532#M182866</link>
      <description>&lt;P&gt;Hopefully, in 6.1.4+  / 6.2+ manually deleting pid files should not be necessary.&lt;BR /&gt;
If it is, please do a little investigation of the system state, file contents, etc and file a bug.&lt;/P&gt;</description>
      <pubDate>Sun, 05 Oct 2014 00:32:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-unable-to-start-and-emits-quot-Conf-is-currently-being/m-p/101532#M182866</guid>
      <dc:creator>jrodman</dc:creator>
      <dc:date>2014-10-05T00:32:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk unable to start and emits "Conf is currently being modified by process ####."</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-unable-to-start-and-emits-quot-Conf-is-currently-being/m-p/101533#M182867</link>
      <description>&lt;P&gt;splunkd.pid.corrupt is not used.  That comes to exist if splunk does not trust the contents of the file splunkd.pid.  splunkd will rename the splunkd.pid to splunkd.pid.corrupt if it believes it's broken (such as containing process id 1, or not containing an identifiable sequence of numbers).&lt;/P&gt;</description>
      <pubDate>Sun, 05 Oct 2014 00:35:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-unable-to-start-and-emits-quot-Conf-is-currently-being/m-p/101533#M182867</guid>
      <dc:creator>jrodman</dc:creator>
      <dc:date>2014-10-05T00:35:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk unable to start and emits "Conf is currently being modified by process ####."</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-unable-to-start-and-emits-quot-Conf-is-currently-being/m-p/101534#M182868</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/1357"&gt;@yannK&lt;/a&gt;, it seems not applicable for me. I still cant bring up the splunk web interface. Any other advise?&lt;/P&gt;

&lt;P&gt;In addition, i found this under */log/splunk:&lt;/P&gt;

&lt;P&gt;[build 255606] 2015-07-01 11:03:45&lt;BR /&gt;
 C++ exception: object@[0x000000000692ED80], type@[0x0000000140FAEF60]&lt;BR /&gt;
 Exception is Non-continuable&lt;BR /&gt;
 Exception address: [0x000007FEFDF3ADCD]&lt;BR /&gt;
 Crashing thread: IndexerTPoolWorker-0&lt;BR /&gt;
    MxCsr:  [0x0000000000001F80]&lt;BR /&gt;
    SegDs:  [0x000000000000002B]&lt;BR /&gt;
    SegEs:  [0x000000000000002B]&lt;BR /&gt;
    SegFs:  [0x0000000000000053]&lt;BR /&gt;
    SegGs:  [0x000000000000002B]&lt;BR /&gt;
    SegSs:  [0x000000000000002B]&lt;BR /&gt;
    SegCs:  [0x0000000000000033]&lt;BR /&gt;
    EFlags:  [0x0000000000000202]&lt;BR /&gt;
    Rsp:  [0x000000000692EB70]&lt;BR /&gt;
    Rip:  [0x000007FEFDF3ADCD] RaiseException + 61/80&lt;BR /&gt;
    Dr0:  [0x0000000000000000]&lt;BR /&gt;
    Dr1:  [0x0000000000000000]&lt;BR /&gt;
    Dr2:  [0x000000000692E628]&lt;BR /&gt;
    Dr3:  [0x0000000000000000]&lt;BR /&gt;
    Dr6:  [0x000007FEDA2F24A3]&lt;BR /&gt;
    Dr7:  [0x0000000000000000]&lt;BR /&gt;
    Rax:  [0x000000006113A801]&lt;BR /&gt;
    Rcx:  [0x000000000692E560]&lt;BR /&gt;
    Rdx:  [0x00000000000000D0]&lt;BR /&gt;
    Rbx:  [0x0000000140FAEF60]&lt;BR /&gt;
    Rbp:  [0x000000000692ECA0]&lt;BR /&gt;
    Rsi:  [0x00000000039DC248]&lt;BR /&gt;
    Rdi:  [0x00000000039EE290]&lt;BR /&gt;
    R8:  [0x0000000000000000]&lt;BR /&gt;
    R9:  [0x0000000000000000]&lt;BR /&gt;
    R10:  [0x000000013F470000]&lt;BR /&gt;
    R11:  [0x000000000692EBB0]&lt;BR /&gt;
    R12:  [0x000000000692F3D8]&lt;BR /&gt;
    R13:  [0x00000000039DC1C0]&lt;BR /&gt;
    R14:  [0x0000000000000000]&lt;BR /&gt;
    R15:  [0x00000000039DC1C0]&lt;BR /&gt;
    DebugControl:  [0xFFFFFFFFFFFFFFFE]&lt;BR /&gt;
    LastBranchToRip:  [0x0000000000000018]&lt;BR /&gt;
    LastBranchFromRip:  [0x0000000000000000]&lt;BR /&gt;
    LastExceptionToRip:  [0x0000000005490010]&lt;BR /&gt;
    LastExceptionFromRip:  [0x000000013FFC3380]&lt;/P&gt;

&lt;P&gt;OS: Windows&lt;BR /&gt;
 Arch: x86-64&lt;/P&gt;

&lt;P&gt;Backtrace:&lt;BR /&gt;
  [0x000007FEFDF3ADCD] RaiseException + 61/80&lt;BR /&gt;
Args:  [0x0000000140FAEF60]  [0x000000000692ECB0]  [0x0000000000000001]&lt;BR /&gt;
  [0x000007FEDA31E92C] CxxThrowException + 212/1124&lt;BR /&gt;
Args:  [0x000000013F470000]  [0x0000000000000108]  [0x0000000000000108]&lt;BR /&gt;
  [0x000000013F69B74F] ?&lt;BR /&gt;
Args:  [0x0000000000000000]  [0x00000000039DD120]  [0x000033A054A45C0A]&lt;BR /&gt;
  [0x000000013F69AE53] ?&lt;BR /&gt;
Args:  [0x000000000692F480]  [0x0000000003993C48]  [0x00000000039DC280]&lt;BR /&gt;
  [0x000000013F69E5E3] ?&lt;BR /&gt;
Args:  [0x0000000003990AF0]  [0x00000000039DC280]  [0x00000000039DC280]&lt;BR /&gt;
  [0x000000013F69340E] ?&lt;BR /&gt;
Args:  [0x0000000000000000]  [0x00000000043B9980]  [0x0000000003987AB0]&lt;BR /&gt;
  [0x000000013F6CC427] ?&lt;BR /&gt;
Args:  [0x00000000039DC1C0]  [0x0000000003987AB0]  [0x0000000000000800]&lt;BR /&gt;
  [0x000000013F6CBE56] ?&lt;BR /&gt;
Args:  [0x0000000000000001]  [0x0000000003987AB0]  [0x0000000000000000]&lt;BR /&gt;
  [0x000000013F6D2D4B] ?&lt;BR /&gt;
Args:  [0x0000000004382018]  [0x00000000043A96B0]  [0x0000000000000000]&lt;BR /&gt;
  [0x000000013FA9A668] ?&lt;BR /&gt;
Args:  [0x00000000043A96B0]  [0x00000000043B9980]  [0x00000000024D0F10]&lt;BR /&gt;
  [0x000000013FC69BFC] ?&lt;BR /&gt;
Args:  [0x00000000043B9980]  [0x000007FEDA2E432B]  [0x0000000000000000]&lt;BR /&gt;
  [0x000000013F4A97C7] ?&lt;BR /&gt;
Args:  [0x00000000024D0F10]  [0x0000000000000000]  [0x0000000000000000]&lt;BR /&gt;
  [0x000007FEDA2E3FEF] beginthreadex + 263/284&lt;BR /&gt;
Args:  [0x000007FEDA381DB0]  [0x0000000000000000]  [0x0000000000000000]&lt;BR /&gt;
  [0x000007FEDA2E4196] endthreadex + 402/404&lt;BR /&gt;
Args:  [0x0000000000000000]  [0x0000000000000000]  [0x0000000000000000]&lt;BR /&gt;
  [0x00000000770E59DD] BaseThreadInitThunk + 13/96&lt;BR /&gt;
Args:  [0x0000000000000000]  [0x0000000000000000]  [0x0000000000000000]&lt;BR /&gt;
  [0x00000000777FA651] RtlUserThreadStart + 33/1024&lt;BR /&gt;
Args:  [0x0000000000000000]  [0x0000000000000000]  [0x0000000000000000]&lt;BR /&gt;
 Crash dump written to: C:\Program Files\Splunk\var\log\splunk\C__Program Files_Splunk_bin_splunkd_exe_crash-2015-07-01-11-03-45.dmp&lt;/P&gt;

&lt;P&gt;Splunk ran as local administratorMW7GDTHS0E4NJD /6.1 Service Pack 1&lt;BR /&gt;
GetLastError(): 0&lt;BR /&gt;
Threads running: 14&lt;BR /&gt;
Executable module base: 0x000000013F470000&lt;BR /&gt;
argv: [Splunkd -p 8089]&lt;BR /&gt;
Thread: "IndexerTPoolWorker-0", did_join=0, ready_to_run=Y, main_thread=N&lt;BR /&gt;
First 4 bytes of Thread token @00000000043B9994:&lt;BR /&gt;
00000000  5c 2f 00 00                                       |\/..|&lt;BR /&gt;
00000004&lt;BR /&gt;
TPool Worker: _shouldJoinAndDelete=N, _id=0&lt;BR /&gt;
Running TJob: name=TJob&lt;/P&gt;

&lt;P&gt;x86 CPUID registers:&lt;BR /&gt;
         0: 0000000D 756E6547 6C65746E 49656E69&lt;BR /&gt;
         1: 000306A9 01100800 7FBAE3FF BFEBFBFF&lt;BR /&gt;
         2: 76035A01 00F0B2FF 00000000 00CA0000&lt;BR /&gt;
         3: 00000000 00000000 00000000 00000000&lt;BR /&gt;
         4: 1C004121 01C0003F 0000003F 00000000&lt;BR /&gt;
         5: 00000040 00000040 00000003 00021120&lt;BR /&gt;
         6: 00000077 00000002 00000009 00000000&lt;BR /&gt;
         7: 00000000 00000281 00000000 00000000&lt;BR /&gt;
         8: 00000000 00000000 00000000 00000000&lt;BR /&gt;
         9: 00000000 00000000 00000000 00000000&lt;BR /&gt;
         A: 07300403 00000000 00000000 00000603&lt;BR /&gt;
         B: 00000001 00000002 00000100 00000001&lt;BR /&gt;
         C: 00000000 00000000 00000000 00000000&lt;BR /&gt;
         &lt;span class="lia-unicode-emoji" title=":anguished_face:"&gt;😧&lt;/span&gt; 00000007 00000340 00000340 00000000&lt;BR /&gt;
  80000000: 80000008 00000000 00000000 00000000&lt;BR /&gt;
  80000001: 00000000 00000000 00000001 28100800&lt;BR /&gt;
  80000002: 20202020 49202020 6C65746E 20295228&lt;BR /&gt;
  80000003: 65726F43 294D5428 2D356920 30323333&lt;BR /&gt;
  80000004: 5043204D 20402055 30362E32 007A4847&lt;BR /&gt;
  80000005: 00000000 00000000 00000000 00000000&lt;BR /&gt;
  80000006: 00000000 00000000 01006040 00000000&lt;BR /&gt;
  80000007: 00000000 00000000 00000000 00000100&lt;BR /&gt;
  80000008: 00003024 00000000 00000000 00000000&lt;BR /&gt;
terminating...&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 20:26:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-unable-to-start-and-emits-quot-Conf-is-currently-being/m-p/101534#M182868</guid>
      <dc:creator>imanpoeiri</dc:creator>
      <dc:date>2020-09-28T20:26:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk unable to start and emits "Conf is currently being modified by process ####."</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-unable-to-start-and-emits-quot-Conf-is-currently-being/m-p/101535#M182869</link>
      <description>&lt;P&gt;Using 6.3.0, and manually deleting the conf-mutator.pid fixed the same problem for me.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2015 19:48:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-unable-to-start-and-emits-quot-Conf-is-currently-being/m-p/101535#M182869</guid>
      <dc:creator>JeffSchumacher</dc:creator>
      <dc:date>2015-11-06T19:48:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk unable to start and emits "Conf is currently being modified by process ####."</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-unable-to-start-and-emits-quot-Conf-is-currently-being/m-p/101536#M182870</link>
      <description>&lt;P&gt;Removing conf-mutator.pid and restarting worked for me.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jun 2016 18:27:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-unable-to-start-and-emits-quot-Conf-is-currently-being/m-p/101536#M182870</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2016-06-03T18:27:09Z</dc:date>
    </item>
  </channel>
</rss>

