Getting Data In

BucketMover moving to cold on UNC

jrich523
Path Finder

I get the following error:

ERROR BucketMover - aborting move because recursive copy from src='C:\Program Files\Splunk\var\lib\splunk\f5test\warmdb\db_1380909713_1380904989_18' to dst='\10.20.120.120\Splunk\Node01\F5test\inflight-db_1380909713_1380904989_18' failed (reason='The operation completed successfully.')

I is indication successful but i check the folder and there is nothing there.

I logged in to the server (windows 2012 R2) as the service account that runs splunkd and checked to make sure access was ok and im able to create/read/write ok. Also it created the F5Test folder when i added the cold path to the index so its not an access issue.

I ran procmon to see if it showed anything and I can see it trying to access the path

1:42:54.2746637 PM splunkd.exe 1684 CreateFile \10.20.120.120\splunk\Node01\F5test\inflight-db_1380909713_1380904989_18 NAME NOT FOUND Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a

So that seems normal, based on the fact that the file isnt there and it should be the Copy (CreateFile is used for a lot of things)

Is there something else i can do to look at why this might not be working?

thanks

0 Karma
1 Solution

jrich523
Path Finder

one part I left out, that was important to solving this was that i had moved the Warm files previously and it had screwed up the permissions so the problem was i didnt have access to move the local files. reset permissions and things started to move.

View solution in original post

jrich523
Path Finder

one part I left out, that was important to solving this was that i had moved the Warm files previously and it had screwed up the permissions so the problem was i didnt have access to move the local files. reset permissions and things started to move.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...