Deployment Architecture

Cluster Master Error or indexer error - Splunk 7.2.3

halbeisendv
Path Finder

We started Splunk and while the messages were scrolling it stopped on the windows index. It just sits, no additional error messages in splunkd.log Not certain what's happening here.

07-29-2019 16:20:10.473 +0000 INFO DatabaseDirectoryManager - Finished writing bucket manifest in hotWarmPath=/splunk/threathunting/db
07-29-2019 16:20:10.485 +0000 INFO DatabaseDirectoryManager - Start-up refreshing bucket manifest index=webserverlog
07-29-2019 16:20:10.494 +0000 INFO CMBucketId - CMIndexId: New indexName=webserverlog inserted, mapping to id=27
07-29-2019 16:20:12.798 +0000 INFO DatabaseDirectoryManager - idx=webserverlog Writing a bucket manifest in hotWarmPath='/splunk/webserverlog/db', pendingBucketUpdates=0 . Reason='Refreshing manifest at start-up.'
07-29-2019 16:20:12.867 +0000 INFO DatabaseDirectoryManager - Finished writing bucket manifest in hotWarmPath=/splunk/webserverlog/db
07-29-2019 16:20:12.877 +0000 INFO DatabaseDirectoryManager - Start-up refreshing bucket manifest index=wiki
07-29-2019 16:20:12.884 +0000 INFO CMBucketId - CMIndexId: New indexName=wiki inserted, mapping to id=28
07-29-2019 16:20:13.662 +0000 INFO DatabaseDirectoryManager - idx=wiki Writing a bucket manifest in hotWarmPath='/splunk/wiki/db', pendingBucketUpdates=0 . Reason='Refreshing manifest at start-up.'
07-29-2019 16:20:13.684 +0000 INFO DatabaseDirectoryManager - Finished writing bucket manifest in hotWarmPath=/splunk/wiki/db
07-29-2019 16:20:13.692 +0000 INFO DatabaseDirectoryManager - Start-up refreshing bucket manifest index=windows
07-29-2019 16:20:13.696 +0000 INFO CMBucketId - CMIndexId: New indexName=windows inserted, mapping to id=29

0 Karma

harsmarvania57
Ultra Champion

Can you please provide more information ? What is happening, splunk crashed on CM or Indexers or any other issue ?

0 Karma

halbeisendv
Path Finder

Nothing is happening. The log file stops logging at the precise location listed above on multiple restarts.

0 Karma

harsmarvania57
Ultra Champion

I am still not getting what happens after logs stop updating, once logs stopped updating Splunk process crashed on Indexer or Cluster Master ? Have you checked permission of $SPLUNK_HOME/var/lib/splunk/windows directory and sub-directories on Indexers ?

Any ERROR or WARN log messages on Cluster Master ?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...