Getting Data In

Splunk 6.4.1 migration to new Server

drewsunderland
Explorer

Hello All,

I am having one heck of a time migrating an old server to a new server, both are windows server 2012 r2 with Splunk Enterprise 6.4.1 installed, I have followed the instructions here https://answers.splunk.com/answers/583396/what-is-the-full-process-to-migrate-a-full-splunk-1.html

But when I try this and try to install splunk it fails and rolls back, now if I tell it to not start splunk it installs but I cannot get the splunkd server to start, it keeps giving me an error "Access violation, cannot read at address [0x000000000000020]" in the Splunkd crash log. I am completely out of ideas. The new server is a different IP address and Host name.

Thank you,

0 Karma
1 Solution

drewsunderland
Explorer

I figured out what was causing my issue, there was some frozen buckets configured in an app pointing to a drive that does not exist on the new server, after editing the index file and the server.conf file to change the location of the frozen buckets it was able to install successfully and it has all my data.

Thank you again

View solution in original post

drewsunderland
Explorer

I figured out what was causing my issue, there was some frozen buckets configured in an app pointing to a drive that does not exist on the new server, after editing the index file and the server.conf file to change the location of the frozen buckets it was able to install successfully and it has all my data.

Thank you again

drewsunderland
Explorer

Sorry for the late reply,
We are using a domain account, the password is correct, the service starts and windows shows that it is running but as soon as you refresh the services it is stopped, so when reviewing the splunkd crash log it gets the above error.

0 Karma

xpac
SplunkTrust
SplunkTrust

I don't have a good idea on this - I'd open a support case with Splunk, they might need to do some investigation on this.

0 Karma

xpac
SplunkTrust
SplunkTrust

Just a wild guess: Did you change the user Splunk is running as?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...