Archive

Why do the indexes disappear in Settings>Indexes after upgrade to v7.0.2 from v6.6.2?

johnmai
New Member

Currently being hosted on Win2012 R2.

Splunk is installed on C:\ and E:\, with splunk-launch.conf pointing to E:..

However once I complete the upgrade, the indexes disappear from the Webpage Splunk > Settings > Indexes but the search is still working.
I can create a new index which ends up in E:\ but after creation it doesn't appear within Settings > Indexes.

Error:
Installed Files Integrity Checker: Unable to access or parse the contents of manifest file in SPLUNK_HOME directory. As a result, file integrity information is not available. Verify manifest file in SPLUNK_HOME directory is still present, and that the splunk service user context will have read-access.

Confirmed using same account which originally installed Splunk v6.6.2

0 Karma

valiquet
Contributor

Are you on a distributed env?

0 Karma

p_gurav
Champion

Can you check the value of $SPLUNK_HOME?

0 Karma

johnmai
New Member

It's pointing to E:\Splunk\index

And the indexes are E:\Splunk\index\var\lib\splunk

0 Karma

adonio
SplunkTrust
SplunkTrust

can you elaborate?
what does it mean splunk installed on C:\ and E:\?
where are the splunk binaries?
can you share your full splunk-launch.conf including:

SPLUNK_HOME
SPLUNK_DB

when you are running the command | dbinspect or | rest /services/data/indexes | table title homePath_expanded coldPath_expanded
what are the results?

0 Karma