Getting Data In

Splunk 6.4.1 migration to new Server

drewsunderland
Explorer

Hello All,

I am having one heck of a time migrating an old server to a new server, both are windows server 2012 r2 with Splunk Enterprise 6.4.1 installed, I have followed the instructions here https://answers.splunk.com/answers/583396/what-is-the-full-process-to-migrate-a-full-splunk-1.html

But when I try this and try to install splunk it fails and rolls back, now if I tell it to not start splunk it installs but I cannot get the splunkd server to start, it keeps giving me an error "Access violation, cannot read at address [0x000000000000020]" in the Splunkd crash log. I am completely out of ideas. The new server is a different IP address and Host name.

Thank you,

0 Karma
1 Solution

drewsunderland
Explorer

I figured out what was causing my issue, there was some frozen buckets configured in an app pointing to a drive that does not exist on the new server, after editing the index file and the server.conf file to change the location of the frozen buckets it was able to install successfully and it has all my data.

Thank you again

View solution in original post

drewsunderland
Explorer

I figured out what was causing my issue, there was some frozen buckets configured in an app pointing to a drive that does not exist on the new server, after editing the index file and the server.conf file to change the location of the frozen buckets it was able to install successfully and it has all my data.

Thank you again

drewsunderland
Explorer

Sorry for the late reply,
We are using a domain account, the password is correct, the service starts and windows shows that it is running but as soon as you refresh the services it is stopped, so when reviewing the splunkd crash log it gets the above error.

0 Karma

xpac
SplunkTrust
SplunkTrust

I don't have a good idea on this - I'd open a support case with Splunk, they might need to do some investigation on this.

0 Karma

xpac
SplunkTrust
SplunkTrust

Just a wild guess: Did you change the user Splunk is running as?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...