Deployment Architecture

How to re-enable an index that was disabled after migrating Splunk indexer from Windows to Linux?

skoelpin
SplunkTrust
SplunkTrust

I'm in the process of moving my standalone indexer from Windows to Linux. I'm in the last part of my journey of moving the data over to the new index. After moving my Windows DB file full of data to the new Linux DB file (overwriting) and restarting Splunk, I noticed my index is disabled. I attempted to enable the index but it does not work..

I'm suspecting the issue is a bucket_id collision, but not 100% sure.. how can I fix this so the index is enabled?

0 Karma
1 Solution

skoelpin
SplunkTrust
SplunkTrust

I just found the issue! I had duplicate bucket names in %SPLUNK_HOME/var/lib/splunk/.../db

To solve the issue I just appended a number to the bucket and restarted Splunk

View solution in original post

skoelpin
SplunkTrust
SplunkTrust

I just found the issue! I had duplicate bucket names in %SPLUNK_HOME/var/lib/splunk/.../db

To solve the issue I just appended a number to the bucket and restarted Splunk

nsanchezfernand
Path Finder

Hi, Skoelpin

I have had the same issue. Because of duplicated bucket names in Splunk, it has automatically disabled the majority of my indexes. I have identified the buckets with duplicated names and I have stop Splunk, renamed them to other non duplicated names, and start Splunk, but the data of my indexes seems to be deleted (search does not return nothing). In the directory of the buckets (db) there is data, and I don't know why is not returning data.

Had you done any additional thing to make work the index after change the name of the bucket?

Thanks!!!

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...