Getting Data In

Splunk Issue

daniel333
Builder

Good morning,

Still VERY new to Splunk here. But I had a issue I was looking for input on where to start with troubleshooting.

Our company has an index splunk service die somepoint yesterday. I started it again with ./splunk start and it went into a fsck mode and was doing that for roughly an hour then worked. This mornming A different indexer has the same issue.

Any idea what could be happening? Where I would start troubleshooting something like that?

Tags (3)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Well, I guess I would check for a crash log and see if there was any unusual activity (CPU, disk, memory) according to any data you gathered, as well as the splunk internal logs files. Those are in $SPLUNK_HOME/var/log/splunk, but also indexed into the _internal index.

Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...