<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: After indexer cluster upgrade to Splunk 6.3, why are we getting search error &amp;quot;Streamed search execute failed because: JournalSliceDirectory: Cannot seek to 0&amp;quot;? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/After-indexer-cluster-upgrade-to-Splunk-6-3-why-are-we-getting/m-p/231225#M68571</link>
    <description>&lt;P&gt;We have 9 indexers, I went through all of them and no mismatching file permissions were found. That is what Splunk support told me to check before they went silent.&lt;/P&gt;</description>
    <pubDate>Mon, 15 Feb 2016 20:42:37 GMT</pubDate>
    <dc:creator>rozmar564</dc:creator>
    <dc:date>2016-02-15T20:42:37Z</dc:date>
    <item>
      <title>After indexer cluster upgrade to Splunk 6.3, why are we getting search error "Streamed search execute failed because: JournalSliceDirectory: Cannot seek to 0"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/After-indexer-cluster-upgrade-to-Splunk-6-3-why-are-we-getting/m-p/231218#M68564</link>
      <description>&lt;P&gt;We have Splunk Enterprise and our cluster consists of 3 search heads and 9 search peers. After upgrading to version 6.3, the following started to happen.&lt;/P&gt;

&lt;P&gt;Although the cluster in total has enough space, certain peers from time to time fill up the disk and the splunkd process dies, pushing the cluster into re-organizing the data. After bringing back the dead peer and waiting for the cluster to be 100% operational (meet its search factor and replication factor) many of the searches produce the following errors :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;3 errors occurred while the search was executing. Therefore, search results might be incomplete. Hide errors. [spl003.ayisnap.com] Streamed search execute failed because: JournalSliceDirectory: Cannot seek to 0 [spl008.ayisnap.com] Streamed search execute failed because: JournalSliceDirectory: Cannot seek to 0 [spl009.ayisnap.com] Streamed search execute failed because: JournalSliceDirectory: Cannot seek to 0
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I have no clue how to fix this (I could not find any useful info about this on the internet) and the results are incomplete - our business cannot operate correctly as we take decisions based on the analysis we run using Splunk.&lt;/P&gt;

&lt;P&gt;Could somebody point me to the right direction?&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2015 14:48:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/After-indexer-cluster-upgrade-to-Splunk-6-3-why-are-we-getting/m-p/231218#M68564</guid>
      <dc:creator>rozmar564</dc:creator>
      <dc:date>2015-11-10T14:48:34Z</dc:date>
    </item>
    <item>
      <title>Re: After indexer cluster upgrade to Splunk 6.3, why are we getting search error "Streamed search execute failed because: JournalSliceDirectory: Cannot seek to 0"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/After-indexer-cluster-upgrade-to-Splunk-6-3-why-are-we-getting/m-p/231219#M68565</link>
      <description>&lt;P&gt;Update: I have opened a support case with Splunk Enterprise Support 6 days ago - nobody picked up the support ticket yet... Not cool after paying so much $$$ &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Nov 2015 14:26:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/After-indexer-cluster-upgrade-to-Splunk-6-3-why-are-we-getting/m-p/231219#M68565</guid>
      <dc:creator>rozmar564</dc:creator>
      <dc:date>2015-11-17T14:26:53Z</dc:date>
    </item>
    <item>
      <title>Re: After indexer cluster upgrade to Splunk 6.3, why are we getting search error "Streamed search execute failed because: JournalSliceDirectory: Cannot seek to 0"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/After-indexer-cluster-upgrade-to-Splunk-6-3-why-are-we-getting/m-p/231220#M68566</link>
      <description>&lt;P&gt;any update at this stage? - were seeing this too, typically after a restart (v6.3.1)&lt;/P&gt;</description>
      <pubDate>Wed, 02 Dec 2015 22:31:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/After-indexer-cluster-upgrade-to-Splunk-6-3-why-are-we-getting/m-p/231220#M68566</guid>
      <dc:creator>t9445</dc:creator>
      <dc:date>2015-12-02T22:31:41Z</dc:date>
    </item>
    <item>
      <title>Re: After indexer cluster upgrade to Splunk 6.3, why are we getting search error "Streamed search execute failed because: JournalSliceDirectory: Cannot seek to 0"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/After-indexer-cluster-upgrade-to-Splunk-6-3-why-are-we-getting/m-p/231221#M68567</link>
      <description>&lt;P&gt;not yet - we have 2 open tickets with Support open, and I had to upload a diag to them, this was a week ago. since them nothing. I will call our sales rep and ask if they can nudge the support - this is crazy&lt;/P&gt;</description>
      <pubDate>Wed, 02 Dec 2015 22:39:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/After-indexer-cluster-upgrade-to-Splunk-6-3-why-are-we-getting/m-p/231221#M68567</guid>
      <dc:creator>rozmar564</dc:creator>
      <dc:date>2015-12-02T22:39:50Z</dc:date>
    </item>
    <item>
      <title>Re: After indexer cluster upgrade to Splunk 6.3, why are we getting search error "Streamed search execute failed because: JournalSliceDirectory: Cannot seek to 0"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/After-indexer-cluster-upgrade-to-Splunk-6-3-why-are-we-getting/m-p/231222#M68568</link>
      <description>&lt;P&gt;Any luck?  I'm having a similar issue on a search peer but only for a specific index and a specific date range that includes 1 particular day. &lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2016 22:49:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/After-indexer-cluster-upgrade-to-Splunk-6-3-why-are-we-getting/m-p/231222#M68568</guid>
      <dc:creator>pj_elia</dc:creator>
      <dc:date>2016-02-12T22:49:48Z</dc:date>
    </item>
    <item>
      <title>Re: After indexer cluster upgrade to Splunk 6.3, why are we getting search error "Streamed search execute failed because: JournalSliceDirectory: Cannot seek to 0"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/After-indexer-cluster-upgrade-to-Splunk-6-3-why-are-we-getting/m-p/231223#M68569</link>
      <description>&lt;P&gt;You didnt happen to execute as root one time and write a few buckets as root, then switch back to a less privileged user did you?  Also found this guy's solution but his problem was a bit different:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/174669/what-do-i-do-if-rebuilding-a-bucket-fails.html"&gt;https://answers.splunk.com/answers/174669/what-do-i-do-if-rebuilding-a-bucket-fails.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Feb 2016 12:14:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/After-indexer-cluster-upgrade-to-Splunk-6-3-why-are-we-getting/m-p/231223#M68569</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2016-02-15T12:14:00Z</dc:date>
    </item>
    <item>
      <title>Re: After indexer cluster upgrade to Splunk 6.3, why are we getting search error "Streamed search execute failed because: JournalSliceDirectory: Cannot seek to 0"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/After-indexer-cluster-upgrade-to-Splunk-6-3-why-are-we-getting/m-p/231224#M68570</link>
      <description>&lt;P&gt;We are looking into upgrading to 6.3 and would like to make sure we don't experience things like this. Please update the case when you have solved the issues. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 15 Feb 2016 12:52:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/After-indexer-cluster-upgrade-to-Splunk-6-3-why-are-we-getting/m-p/231224#M68570</guid>
      <dc:creator>asmunde1</dc:creator>
      <dc:date>2016-02-15T12:52:36Z</dc:date>
    </item>
    <item>
      <title>Re: After indexer cluster upgrade to Splunk 6.3, why are we getting search error "Streamed search execute failed because: JournalSliceDirectory: Cannot seek to 0"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/After-indexer-cluster-upgrade-to-Splunk-6-3-why-are-we-getting/m-p/231225#M68571</link>
      <description>&lt;P&gt;We have 9 indexers, I went through all of them and no mismatching file permissions were found. That is what Splunk support told me to check before they went silent.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Feb 2016 20:42:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/After-indexer-cluster-upgrade-to-Splunk-6-3-why-are-we-getting/m-p/231225#M68571</guid>
      <dc:creator>rozmar564</dc:creator>
      <dc:date>2016-02-15T20:42:37Z</dc:date>
    </item>
    <item>
      <title>Re: After indexer cluster upgrade to Splunk 6.3, why are we getting search error "Streamed search execute failed because: JournalSliceDirectory: Cannot seek to 0"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/After-indexer-cluster-upgrade-to-Splunk-6-3-why-are-we-getting/m-p/231226#M68572</link>
      <description>&lt;P&gt;Update: the issue was never resolved, how ever, we don't experience it anymore. We did a DC move in the mean time and we took down the whole cluster for a good few hours, after starting it back up we ended up with a bunch of duplicate buckets that we were able to remove and since then we don't see this issue. Unfortunately &lt;EM&gt;time&lt;/EM&gt; solved it, but no clue what was the root cause &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Feb 2016 20:44:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/After-indexer-cluster-upgrade-to-Splunk-6-3-why-are-we-getting/m-p/231226#M68572</guid>
      <dc:creator>rozmar564</dc:creator>
      <dc:date>2016-02-15T20:44:47Z</dc:date>
    </item>
    <item>
      <title>Re: After indexer cluster upgrade to Splunk 6.3, why are we getting search error "Streamed search execute failed because: JournalSliceDirectory: Cannot seek to 0"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/After-indexer-cluster-upgrade-to-Splunk-6-3-why-are-we-getting/m-p/231227#M68573</link>
      <description>&lt;P&gt;It's sad to hear this. We faced the same problem after 6.3 had released, got no response on the issue and just moved to previous version 6.2. Next week we'll try to upgrade again this time to 6.3.3. I'm afraid the same errors will arise but we need new apps that work just with 6.3..&lt;BR /&gt;
Here was my question &lt;A href="https://answers.splunk.com/answers/310778/journalslicedirectory-cannot-seek-to-0-and-error20.html"&gt;https://answers.splunk.com/answers/310778/journalslicedirectory-cannot-seek-to-0-and-error20.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2016 13:19:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/After-indexer-cluster-upgrade-to-Splunk-6-3-why-are-we-getting/m-p/231227#M68573</guid>
      <dc:creator>iKate</dc:creator>
      <dc:date>2016-03-16T13:19:14Z</dc:date>
    </item>
    <item>
      <title>Re: After indexer cluster upgrade to Splunk 6.3, why are we getting search error "Streamed search execute failed because: JournalSliceDirectory: Cannot seek to 0"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/After-indexer-cluster-upgrade-to-Splunk-6-3-why-are-we-getting/m-p/231228#M68574</link>
      <description>&lt;P&gt;any updates on this issue please?? &lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2016 09:35:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/After-indexer-cluster-upgrade-to-Splunk-6-3-why-are-we-getting/m-p/231228#M68574</guid>
      <dc:creator>sgundeti</dc:creator>
      <dc:date>2016-07-05T09:35:20Z</dc:date>
    </item>
    <item>
      <title>Re: After indexer cluster upgrade to Splunk 6.3, why are we getting search error "Streamed search execute failed because: JournalSliceDirectory: Cannot seek to 0"?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/After-indexer-cluster-upgrade-to-Splunk-6-3-why-are-we-getting/m-p/231229#M68575</link>
      <description>&lt;P&gt;I know it won't help anymore, but for reference:&lt;/P&gt;

&lt;P&gt;If you are having this issue you may have had a crash or non-clean shutdown and need to repair buckets.&lt;/P&gt;

&lt;P&gt;Please take a look at this wiki:&lt;BR /&gt;
&lt;A href="https://wiki.splunk.com/Community:PostCrashFsckRepair"&gt;https://wiki.splunk.com/Community:PostCrashFsckRepair&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;"splunk fsck --all" should show you what buckets are bad, you can either remove them, or try to repair the bucket &lt;/P&gt;

&lt;P&gt;Useful options are: --include-hots, --log-to--splunkd-log &amp;amp; --ignore-read-error&lt;/P&gt;

&lt;P&gt;USAGE&lt;/P&gt;

&lt;P&gt;Supported modes are: scan, repair, clear-bloomfilter, check-integrity, generate-hash-files&lt;/P&gt;

&lt;P&gt;:= --one-bucket|--all-buckets-one-index|--all-buckets-all-indexes&lt;BR /&gt;
    [--index-name=&lt;NAME&gt;] [--bucket-name=&lt;NAME&gt;] [--bucket-path=&lt;PATH&gt;]&lt;BR /&gt;
    [--include-hots]&lt;BR /&gt;
    [--local-id=&lt;ID&gt;] [--origin-guid=&lt;GUID&gt;]&lt;BR /&gt;
    [--min-ET=&lt;EPOCHSECS&gt;] [--max-LT=&lt;EPOCHSECS&gt;]&lt;/EPOCHSECS&gt;&lt;/EPOCHSECS&gt;&lt;/GUID&gt;&lt;/ID&gt;&lt;/PATH&gt;&lt;/NAME&gt;&lt;/NAME&gt;&lt;/P&gt;

&lt;P&gt;:= [--try-warm-then-cold] [--log-to--splunkd-log] [--debug] [--v]&lt;/P&gt;

&lt;P&gt;fsck repair   [--bloomfilter-only]&lt;BR /&gt;
    [--backfill-always|--backfill-never] [--bloomfilter-output-path=&lt;PATH&gt;]&lt;BR /&gt;
    [--raw-size-only] [--metadata] [--ignore-read-error]&lt;/PATH&gt;&lt;/P&gt;

&lt;P&gt;fsck scan   [--metadata] [--check-bloomfilter-presence-always]&lt;/P&gt;

&lt;P&gt;fsck clear-bloomfilter  &lt;/P&gt;

&lt;P&gt;fsck check-integrity &lt;BR /&gt;
fsck generate-hash-files &lt;/P&gt;

&lt;P&gt;fsck check-rawdata-format &lt;/P&gt;

&lt;P&gt;fsck minify-tsidx --one-bucket --bucket-path= --dont-update-manifest|--home-path=&lt;/P&gt;

&lt;P&gt;Notes:&lt;BR /&gt;
    The mode verb 'make-searchable' is synonym for 'repair'.&lt;BR /&gt;
    The mode 'check-integrity' will verify data integrity for buckets created with the integrity-check feature enabled.&lt;BR /&gt;
    The mode 'generate-hash-files' will create or update bucket-level hashes for buckets which were generated with the integrity-check feature enabled.&lt;BR /&gt;
    The mode 'check-rawdata-format' verifies that the journal format is intact for the selected index buckets (the journal is stored in a valid gzip container and has valid journal structure&lt;BR /&gt;
    Flag --log-to--splunkd-log is intended for calls from within splunkd.&lt;BR /&gt;
    If neither --backfill-always nor --backfill-never are given, backfill decisions will be made per indexes.conf 'maxBloomBackfillBucketAge' and 'createBloomfilter' parameters.&lt;BR /&gt;
    Values of 'homePath' and 'coldPath' will always be read from config; if config is not available, use --one-bucket and --bucket-path but not --index-name.&lt;BR /&gt;
    All &lt;BUCKETSELECTOR&gt; constraints supplied are implicitly ANDed.&lt;BR /&gt;
    Flag --metadata is only applicable when migrating from 4.2 release.&lt;BR /&gt;
    If giving --include-hots, please recall that hot buckets have no bloomfilters.&lt;BR /&gt;
    Not all argument combinations are valid.&lt;BR /&gt;
    If --help found in any argument position, prints this message &amp;amp; quits.&lt;/BUCKETSELECTOR&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2017 23:45:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/After-indexer-cluster-upgrade-to-Splunk-6-3-why-are-we-getting/m-p/231229#M68575</guid>
      <dc:creator>twollenslegel_s</dc:creator>
      <dc:date>2017-07-21T23:45:10Z</dc:date>
    </item>
  </channel>
</rss>

