Deployment Architecture

timeinvertedIndex - Splunk-optimize failed to start for index ../fishbucket/db/db-hot

tpaulsen
Contributor

Hello,

i have installed Splunk 4.1.1. When i look at the -> Status -> Index Health page, i see there is this following warn comeing every 12 seconds:

04-26-2010 16:08:55.680 WARN  timeinvertedIndex - splunk-optimize failed to start for index /opt/splunk/var/lib/splunk/fishbucket/db/db-hot

Is this a bug? And if not, what can i do about it?

Tags (2)
1 Solution

tpaulsen
Contributor

I filed a support case and since we have now Splunk 4.1.7 running i haven´t seen the message anymore.
Guess it got fixed.

View solution in original post

0 Karma

tpaulsen
Contributor

I filed a support case and since we have now Splunk 4.1.7 running i haven´t seen the message anymore.
Guess it got fixed.

0 Karma

tpaulsen
Contributor

The splunk-optimize process can´t run on that subdirectory, since it doesn´t exist. Even if i create it manually, splunk-optimize won´t notice, except by creating another error:

05-11-2010 13:10:40.476 ERROR databasePartitionPolicy - Index is empty refusing to move. oldDirPath=/opt/splunk/splunk/var/lib/splunk/fishbucket/db/db-hot

The other message is still there:

05-11-2010 14:33:52.045 WARN  timeinvertedIndex - splunk-optimize failed to start for index /opt/splunk/var/lib/splunk/fishbucket/db/db-hot

Lowell
Super Champion

tpaulsen
Contributor

Ok. So if it happens sporadic, it´s ok, if it´s happening quite often (in my case every 12 seconds...) it´s bad and i need to open a case with Splunk Support.

0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...