Deployment Architecture

Cluster Master Error or indexer error - Splunk 7.2.3

halbeisendv
Path Finder

We started Splunk and while the messages were scrolling it stopped on the windows index. It just sits, no additional error messages in splunkd.log Not certain what's happening here.

07-29-2019 16:20:10.473 +0000 INFO DatabaseDirectoryManager - Finished writing bucket manifest in hotWarmPath=/splunk/threathunting/db
07-29-2019 16:20:10.485 +0000 INFO DatabaseDirectoryManager - Start-up refreshing bucket manifest index=webserverlog
07-29-2019 16:20:10.494 +0000 INFO CMBucketId - CMIndexId: New indexName=webserverlog inserted, mapping to id=27
07-29-2019 16:20:12.798 +0000 INFO DatabaseDirectoryManager - idx=webserverlog Writing a bucket manifest in hotWarmPath='/splunk/webserverlog/db', pendingBucketUpdates=0 . Reason='Refreshing manifest at start-up.'
07-29-2019 16:20:12.867 +0000 INFO DatabaseDirectoryManager - Finished writing bucket manifest in hotWarmPath=/splunk/webserverlog/db
07-29-2019 16:20:12.877 +0000 INFO DatabaseDirectoryManager - Start-up refreshing bucket manifest index=wiki
07-29-2019 16:20:12.884 +0000 INFO CMBucketId - CMIndexId: New indexName=wiki inserted, mapping to id=28
07-29-2019 16:20:13.662 +0000 INFO DatabaseDirectoryManager - idx=wiki Writing a bucket manifest in hotWarmPath='/splunk/wiki/db', pendingBucketUpdates=0 . Reason='Refreshing manifest at start-up.'
07-29-2019 16:20:13.684 +0000 INFO DatabaseDirectoryManager - Finished writing bucket manifest in hotWarmPath=/splunk/wiki/db
07-29-2019 16:20:13.692 +0000 INFO DatabaseDirectoryManager - Start-up refreshing bucket manifest index=windows
07-29-2019 16:20:13.696 +0000 INFO CMBucketId - CMIndexId: New indexName=windows inserted, mapping to id=29

0 Karma

harsmarvania57
Ultra Champion

Can you please provide more information ? What is happening, splunk crashed on CM or Indexers or any other issue ?

0 Karma

halbeisendv
Path Finder

Nothing is happening. The log file stops logging at the precise location listed above on multiple restarts.

0 Karma

harsmarvania57
Ultra Champion

I am still not getting what happens after logs stop updating, once logs stopped updating Splunk process crashed on Indexer or Cluster Master ? Have you checked permission of $SPLUNK_HOME/var/lib/splunk/windows directory and sub-directories on Indexers ?

Any ERROR or WARN log messages on Cluster Master ?

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...