<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: indexer has stopped working in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/indexer-has-stopped-working/m-p/690233#M235100</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/263224"&gt;@Orange_girl&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;check if you received logs until the 31st of May, if yes and data flow stopped at 1st of June, check the timestamp format because probably you missed a configuration, but until the 31st of May you didn't discover it.&lt;/P&gt;&lt;P&gt;the check the time forma of your data.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 10 Jun 2024 13:09:39 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2024-06-10T13:09:39Z</dc:date>
    <item>
      <title>indexer has stopped working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/indexer-has-stopped-working/m-p/690210#M235094</link>
      <description>&lt;P&gt;Hello Splunk community,&amp;nbsp;&lt;/P&gt;&lt;P&gt;One of my indexes doesn't seem to have indexed any data for the last two weeks or so. This is the logs I see when searching for index="_internal" index_name:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;26/05/2024 02:19:36.947 // 05-26-2024 02:19:36.947 -0400 INFO Dashboard - group=per_index_thruput, series="index_name", kbps=7940.738, eps=17495.842, kb=246192.784, ev=542437, avg_age=0.039, max_age=1&lt;/P&gt;&lt;P&gt;26/05/2024 02:19:07.804 // 05-26-2024 02:19:07.804 -0400 INFO DatabaseDirectoryManager [12112 IndexerService] - Finished writing bucket manifest in hotWarmPath=/opt/splunk/var/lib/splunk/…/db duration=0.013&lt;/P&gt;&lt;P&gt;26/05/2024 02:19:07.799 // 05-26-2024 02:19:07.799 -0400 INFO DatabaseDirectoryManager [12112 IndexerService] - idx=index_name writing a bucket manifest in hotWarmPath='/opt/splunk/var/lib/splunk/…/db' pendingBucketUpdates=0 innerLockTime=0.009. Reason='Buckets were rebuilt or tsidx-minified (bucket_count=1).'&lt;/P&gt;&lt;P&gt;26/05/2024 02:19:05.944 // 05-26-2024 02:19:05.944 -0400 INFO Dashboard - group=per_index_thruput, series="index_name", kbps=10987.030, eps=24200.033, kb=340566.581, ev=750132, avg_age=0.032, max_age=1&lt;/P&gt;&lt;P&gt;26/05/2024 02:18:59.981 // 05-26-2024 02:18:59.981 -0400 INFO LicenseUsage - type=Usage s="/opt/splunk/etc/apps/…/…/ABC.csv" st="name" h=host o="" idx="index_name" i="41050380-CA05-4248-AFCA-93E310A1E6A9" pool="auto_generated_pool_enterprise" b=6343129 poolsz=5368709120&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What could be a reason for this and how could I address it? Thank you for all your help!&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2024 10:17:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/indexer-has-stopped-working/m-p/690210#M235094</guid>
      <dc:creator>Orange_girl</dc:creator>
      <dc:date>2024-06-10T10:17:55Z</dc:date>
    </item>
    <item>
      <title>Re: indexer has stopped working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/indexer-has-stopped-working/m-p/690216#M235095</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/263224"&gt;@Orange_girl&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;please check the time format of your timestamps: maybe they are in european format (dd/mm/yyyy) and you didn't configured TIME_FORMAT in your sourcetype definition, so Splunk uses the american format (mm/dd/yyyy).&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2024 10:51:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/indexer-has-stopped-working/m-p/690216#M235095</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-06-10T10:51:17Z</dc:date>
    </item>
    <item>
      <title>Re: indexer has stopped working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/indexer-has-stopped-working/m-p/690232#M235099</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Giuseppe,&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I haven't changed anything in SPLUNK and the indexing used to work well, would this just randomly change by itself?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I'm happy to check it though, could you let me know where and what I should be looking for? Are you referring to the time value in logs?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;thank you.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2024 13:03:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/indexer-has-stopped-working/m-p/690232#M235099</guid>
      <dc:creator>Orange_girl</dc:creator>
      <dc:date>2024-06-10T13:03:40Z</dc:date>
    </item>
    <item>
      <title>Re: indexer has stopped working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/indexer-has-stopped-working/m-p/690233#M235100</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/263224"&gt;@Orange_girl&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;check if you received logs until the 31st of May, if yes and data flow stopped at 1st of June, check the timestamp format because probably you missed a configuration, but until the 31st of May you didn't discover it.&lt;/P&gt;&lt;P&gt;the check the time forma of your data.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2024 13:09:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/indexer-has-stopped-working/m-p/690233#M235100</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-06-10T13:09:39Z</dc:date>
    </item>
    <item>
      <title>Re: indexer has stopped working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/indexer-has-stopped-working/m-p/690235#M235102</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;SPAN&gt;Giuseppe. The logs I shared here are the last logs I received for this index.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I also checked logs for ABC.csv which is used by the index, and same here - logs only until May 26th:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;26/05/2024 02:19:39.647 // 05-26-2024 02:19:39.647 -0400 WARN TailReader [12321 tailreader0] - Access error while handling path: failed to open for checksum: '/opt/splunk/etc/apps/.../.../ABC.csv' (No such file or directory)&lt;/P&gt;&lt;P&gt;26/05/2024 02:19:38.208 // 05-26-2024 02:19:38.208 -0400 INFO WatchedFile [12321 tailreader0] - Will begin reading at offset=0 for file='/opt/splunk/etc/apps/.../.../ABC.csv'.&lt;/P&gt;&lt;P&gt;26/05/2024 02:19:38.208 // 05-26-2024 02:19:38.208 -0400 INFO WatchedFile [12321 tailreader0] - Checksum for seekptr didn't match, will re-read entire file='/opt/splunk/etc/apps/.../.../ABC.csv'.&lt;/P&gt;&lt;P&gt;26/05/2024 02:19:37.621 // 05-26-2024 02:19:37.621 -0400 WARN TailReader [12321 tailreader0] - Insufficient permissions to read file='/opt/splunk/etc/apps/.../.../ABC' (hint: No such file or directory , UID: 0, GID: 0).&lt;/P&gt;&lt;P&gt;26/05/2024 02:19:37.512 // 05-26-2024 02:19:37.512 -0400 INFO WatchedFile [12321 tailreader0] - Will begin reading at offset=0 for file='/opt/splunk/etc/apps/.../.../ABC.csv'.&lt;/P&gt;&lt;P&gt;26/05/2024 02:19:37.512 // 05-26-2024 02:19:37.512 -0400 WARN LineBreakingProcessor [12299 parsing] - Truncating line because limit of 10000 bytes has been exceeded with a line length &amp;gt;= 50968856 - data_source="/opt/splunk/etc/apps/.../.../ABC.csv", data_host="host", data_sourcetype="sourcetype"&lt;/P&gt;&lt;P&gt;26/05/2024 02:19:37.512 // 05-26-2024 02:19:37.512 -0400 INFO WatchedFile [12321 tailreader0] - Will begin reading at offset=0 for file='/opt/splunk/etc/apps/.../.../ABC.csv'.&lt;/P&gt;&lt;P&gt;26/05/2024 02:19:37.143 // 05-26-2024 02:19:37.143 -0400 WARN LineBreakingProcessor [12299 parsing] - Truncating line because limit of 10000 bytes has been exceeded with a line length &amp;gt;= 50276856 - data_source="/opt/splunk/etc/apps/.../.../ABC.csv", data_host="host", data_sourcetype="sourcetype"&lt;/P&gt;&lt;P&gt;26/05/2024 02:19:36.947 // 05-26-2024 02:19:36.947 -0400 INFO Dashboard - group=per_source_thruput, series="/opt/splunk/etc/apps/.../.../ABC.csv", kbps=219.057, eps=482.877, kb=6791.592, ev=14971, avg_age=0.000, max_age=0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would this be of any help?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2024 13:34:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/indexer-has-stopped-working/m-p/690235#M235102</guid>
      <dc:creator>Orange_girl</dc:creator>
      <dc:date>2024-06-10T13:34:59Z</dc:date>
    </item>
    <item>
      <title>Re: indexer has stopped working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/indexer-has-stopped-working/m-p/690236#M235103</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/263224"&gt;@Orange_girl&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;it seems that something changed: Splunk hasn't more the requested permissions on the files to read: check them.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2024 13:35:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/indexer-has-stopped-working/m-p/690236#M235103</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-06-10T13:35:57Z</dc:date>
    </item>
    <item>
      <title>Re: indexer has stopped working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/indexer-has-stopped-working/m-p/692388#M235664</link>
      <description>&lt;P&gt;I haven't been able to look into this as much as I'd like, however over the past 2 weeks this has randomly worked couple of times - no errors and no issues. I still don't understand how it can complain about not having the right permissions and then suddenly work well the very next day to only again give the errors 2 days later....&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2024 08:39:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/indexer-has-stopped-working/m-p/692388#M235664</guid>
      <dc:creator>Orange_girl</dc:creator>
      <dc:date>2024-07-04T08:39:03Z</dc:date>
    </item>
    <item>
      <title>Re: indexer has stopped working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/indexer-has-stopped-working/m-p/692390#M235665</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;as&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;said there are issues with file permissions.&lt;/P&gt;&lt;P&gt;You should check that those files are owned by your splunk user (usually splunk). Those can be changed e.g. if someone has restarted splunk as root user etc.&lt;/P&gt;&lt;P&gt;One other option is that your file system has remounted as RO due to some OS/storage level issue. Check also this and fix if needed.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2024 08:43:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/indexer-has-stopped-working/m-p/692390#M235665</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-07-04T08:43:22Z</dc:date>
    </item>
  </channel>
</rss>

