Deployment Architecture

What is causing HotBucketRoller errors?

simpkins1958
Contributor

I need to understand what could be causing these errors. Seeing them frequently on one of our sytems.

04-13-2018 07:59:07.751 -0700 WARN HotBucketRoller - Trying again to move bucket from="E:\Program Files\Splunk\var\lib\splunk\nmi_app_dest_survey\db\hot_v1_0" to="E:\Program Files\Splunk\var\lib\splunk\nmi_app_dest_survey\db\db_1515465598_1515283210_0".
04-13-2018 07:59:07.752 -0700 ERROR HotBucketRoller - Unable to rename from='E:\Program Files\Splunk\var\lib\splunk\nmi_app_dest_survey\db\hot_v1_0' to='E:\Program Files\Splunk\var\lib\splunk\nmi_app_dest_survey\db\db_1515465598_1515283210_0' because The system cannot find the file specified.
04-13-2018 07:59:07.752 -0700 ERROR HotBucketRoller - Failed again to move bucket, reason='Unable to rename from='E:\Program Files\Splunk\var\lib\splunk\nmi_app_dest_survey\db\hot_v1_0' to='E:\Program Files\Splunk\var\lib\splunk\nmi_app_dest_survey\db\db_1515465598_1515283210_0' because The system cannot find the file specified.'. Will retry later.

MuS
Legend

Hi simpkins1958,

As @p_gurav already said, check the file system or folder permissions.

Running Splunk on Windows is a pain and you just hit one of many issues - for a long list of issues see this post: https://answers.splunk.com/answers/516059/what-are-the-pain-points-with-deploying-your-splun.html

cheers, MuS

0 Karma

p_gurav
Champion

Can you check folder permission?

samratgavale
Explorer

I am too facing this error in some of my indexers. When I look at the path mentioned in the error, indeed that particular directory does not exists.

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

New This Month - Observability Updates Give Extended Visibility and Improve User ...

This month is a collection of special news! From Magic Quadrant updates to AppDynamics integrations to ...

Intro to Splunk Synthetic Monitoring

In our last post, we mentioned that the 3 key pieces of observability – metrics, logs, and traces – provide ...