Getting Data In

Unable to Start Splunk Service on Windows- failed with ERROR ConfObjectManagerDB - Cannot initialize: D:\Program Files\Splunk\etc\apps\ learned\metadata\default.meta: The operation completed successfully."

rbal_splunk
Splunk Employee
Splunk Employee

We are able to start splunk services - But getting following error while starting the services in Heavy Forwarder

"ERROR ConfObjectManagerDB - Cannot initialize: D:\Program Files\Splunk\etc\apps\
learned\metadata\default.meta: The operation completed successfully."

When I tried to launch the file default.meta file - It gives me an error as access denied. I am using Admin account to launch the file - Getting same message even after stopping the splunk services.

Tried to replace file from back up - still getting message as - I don’t have access to the perform the operation.

Tags (3)
0 Karma

rbal_splunk
Splunk Employee
Splunk Employee

I will suggest you to try steps recommend below, before performing these steps please stop the splunk service.

From windows explorer- navigate to the Splunk folder and right click on the Splunk Properties
In the ‘Splunk Properties’, click on tab ‘Security’
On the Security Tab, click on “Advanced”.
Now you will be in context of ‘Advanced Security Setting for Splunk”, here click on ‘Owner’.

You will see the list of owner, here click ‘Edit’, where you can pick the user who will run the splunk service.
Once you pickup the user , select check box “Replace owner on sub containers and objects” and Apply.
Please restart the Splunk service and see if it helps.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...