Getting Data In

Unable to Start Splunk Service on Windows- failed with ERROR ConfObjectManagerDB - Cannot initialize: D:\Program Files\Splunk\etc\apps\ learned\metadata\default.meta: The operation completed successfully."

rbal_splunk
Splunk Employee
Splunk Employee

We are able to start splunk services - But getting following error while starting the services in Heavy Forwarder

"ERROR ConfObjectManagerDB - Cannot initialize: D:\Program Files\Splunk\etc\apps\
learned\metadata\default.meta: The operation completed successfully."

When I tried to launch the file default.meta file - It gives me an error as access denied. I am using Admin account to launch the file - Getting same message even after stopping the splunk services.

Tried to replace file from back up - still getting message as - I don’t have access to the perform the operation.

Tags (3)
0 Karma

rbal_splunk
Splunk Employee
Splunk Employee

I will suggest you to try steps recommend below, before performing these steps please stop the splunk service.

From windows explorer- navigate to the Splunk folder and right click on the Splunk Properties
In the ‘Splunk Properties’, click on tab ‘Security’
On the Security Tab, click on “Advanced”.
Now you will be in context of ‘Advanced Security Setting for Splunk”, here click on ‘Owner’.

You will see the list of owner, here click ‘Edit’, where you can pick the user who will run the splunk service.
Once you pickup the user , select check box “Replace owner on sub containers and objects” and Apply.
Please restart the Splunk service and see if it helps.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...