Deployment Architecture

Cluster Master Error or indexer error - Splunk 7.2.3

halbeisendv
Path Finder

We started Splunk and while the messages were scrolling it stopped on the windows index. It just sits, no additional error messages in splunkd.log Not certain what's happening here.

07-29-2019 16:20:10.473 +0000 INFO DatabaseDirectoryManager - Finished writing bucket manifest in hotWarmPath=/splunk/threathunting/db
07-29-2019 16:20:10.485 +0000 INFO DatabaseDirectoryManager - Start-up refreshing bucket manifest index=webserverlog
07-29-2019 16:20:10.494 +0000 INFO CMBucketId - CMIndexId: New indexName=webserverlog inserted, mapping to id=27
07-29-2019 16:20:12.798 +0000 INFO DatabaseDirectoryManager - idx=webserverlog Writing a bucket manifest in hotWarmPath='/splunk/webserverlog/db', pendingBucketUpdates=0 . Reason='Refreshing manifest at start-up.'
07-29-2019 16:20:12.867 +0000 INFO DatabaseDirectoryManager - Finished writing bucket manifest in hotWarmPath=/splunk/webserverlog/db
07-29-2019 16:20:12.877 +0000 INFO DatabaseDirectoryManager - Start-up refreshing bucket manifest index=wiki
07-29-2019 16:20:12.884 +0000 INFO CMBucketId - CMIndexId: New indexName=wiki inserted, mapping to id=28
07-29-2019 16:20:13.662 +0000 INFO DatabaseDirectoryManager - idx=wiki Writing a bucket manifest in hotWarmPath='/splunk/wiki/db', pendingBucketUpdates=0 . Reason='Refreshing manifest at start-up.'
07-29-2019 16:20:13.684 +0000 INFO DatabaseDirectoryManager - Finished writing bucket manifest in hotWarmPath=/splunk/wiki/db
07-29-2019 16:20:13.692 +0000 INFO DatabaseDirectoryManager - Start-up refreshing bucket manifest index=windows
07-29-2019 16:20:13.696 +0000 INFO CMBucketId - CMIndexId: New indexName=windows inserted, mapping to id=29

0 Karma

harsmarvania57
Ultra Champion

Can you please provide more information ? What is happening, splunk crashed on CM or Indexers or any other issue ?

0 Karma

halbeisendv
Path Finder

Nothing is happening. The log file stops logging at the precise location listed above on multiple restarts.

0 Karma

harsmarvania57
Ultra Champion

I am still not getting what happens after logs stop updating, once logs stopped updating Splunk process crashed on Indexer or Cluster Master ? Have you checked permission of $SPLUNK_HOME/var/lib/splunk/windows directory and sub-directories on Indexers ?

Any ERROR or WARN log messages on Cluster Master ?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...