<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I resolve this error in index: _internal? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-resolve-this-error-in-index-internal/m-p/641191#M222145</link>
    <description>&lt;P&gt;Error #1 should not reference the search log since there is nothing in the message that tells us what search is reported the error. You can ignore that suggestion.&amp;nbsp; You can, however, use the fsck command to attempt to repair the file.&lt;/P&gt;&lt;P&gt;The other two error messages do not provide enough information to diagnose or fix anything.&amp;nbsp; Unless there are other messages that offer more context or information then you can ignore the error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 24 Apr 2023 20:05:56 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2023-04-24T20:05:56Z</dc:date>
    <item>
      <title>How do I resolve this error in index: _internal?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-resolve-this-error-in-index-internal/m-p/641132#M222123</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;
&lt;P&gt;I am searching for corrupt data in Splunk, and thus executed the below query: -&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index=_internal sourcetype=splunk_search_messages "corrupt" OR "corrupted"&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I got the below errors: -&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Error 1: -&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;message=[wd*****] [subsearch]: Failed to read size=4 event(s) from rawdata in bucket='dummyIndex~119~8X88XXY-X8XX-88X8-888X-X88X88XX8888' path='/u01/ovz/data/dummyIndex/db/db_1611661166_1611222333_111_8X88XX8X-X8XX-88X8-888X-X88X88XX8888. Rawdata may be corrupt, see search.log.&amp;nbsp; Results may be incomplete!&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Error 2: -&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;01-01-2023 07:01:01.098 ERROR SRSSerializer [12729 RemoteTimelineReadThread] - cannot read file magic -probably corrupt&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Error 3: -&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Error decompressing zstd block: Corrupted block detected&lt;/P&gt;
&lt;P&gt;I need your help to understand and get details about the above errors, Error 1, Error 2 and Error 3.&lt;/P&gt;
&lt;P&gt;In Error 1, it states to check search.log. Thus, it would be helpful if you can share how to fetch the relevant information from the file.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So far for error 1, I found&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Splunk-Search/Searchquery-error/m-p/509508" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Splunk-Search/Searchquery-error/m-p/509508&lt;/A&gt;&amp;nbsp;which states that file may be corrupt.&lt;/P&gt;
&lt;P&gt;Any information about the above two errors will be very helpful.&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2023 19:03:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-resolve-this-error-in-index-internal/m-p/641132#M222123</guid>
      <dc:creator>Taruchit</dc:creator>
      <dc:date>2023-04-24T19:03:45Z</dc:date>
    </item>
    <item>
      <title>Re: How do I resolve this Error in index: _internal?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-resolve-this-error-in-index-internal/m-p/641179#M222139</link>
      <description>&lt;P&gt;For error 1, I fetched following details on&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.4/Indexer/HowSplunkstoresindexes:" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.4/Indexer/HowSplunkstoresindexes:&lt;/A&gt;&amp;nbsp;-&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;db_1611661166_1611222333_111_8X88XX8X-X8XX-88X8-888X-X88X88XX8888&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;db: Originating bucket&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;1611661166: Newest time&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;1611222333: Oldest time&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;111: localid; ID for the bucket&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;8X88XX8X-X8XX-88X8-888X-X88X88XX8888: guid; guid of the source peer node&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Mon, 24 Apr 2023 18:39:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-resolve-this-error-in-index-internal/m-p/641179#M222139</guid>
      <dc:creator>Taruchit</dc:creator>
      <dc:date>2023-04-24T18:39:30Z</dc:date>
    </item>
    <item>
      <title>Re: How do I resolve this error in index: _internal?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-resolve-this-error-in-index-internal/m-p/641191#M222145</link>
      <description>&lt;P&gt;Error #1 should not reference the search log since there is nothing in the message that tells us what search is reported the error. You can ignore that suggestion.&amp;nbsp; You can, however, use the fsck command to attempt to repair the file.&lt;/P&gt;&lt;P&gt;The other two error messages do not provide enough information to diagnose or fix anything.&amp;nbsp; Unless there are other messages that offer more context or information then you can ignore the error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2023 20:05:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-resolve-this-error-in-index-internal/m-p/641191#M222145</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-04-24T20:05:56Z</dc:date>
    </item>
    <item>
      <title>Re: How do I resolve this Error in index: _internal?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-resolve-this-error-in-index-internal/m-p/641192#M222146</link>
      <description>&lt;P&gt;That is the correct breakdown of a bucket name.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2023 20:07:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-resolve-this-error-in-index-internal/m-p/641192#M222146</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-04-24T20:07:02Z</dc:date>
    </item>
  </channel>
</rss>

