Getting Data In

"Indexer was started dirty"

krussell101
Path Finder

I have no clue what this error means.

The entire error in the splunkd.log is:

Indexer was started dirty, searches may not be accurate. Consider restarting Splunk and accepting the recovery request.

When I stop and restart splunk I'm not offered a recovery option.

I am getting these on virtually every server where I'm running splunk. Heavy forwarders and the indexer itself. The only exception are the two servers where I am running universal forwarders.

What does it mean and how do I clear it?

Thanks!!!

Tags (1)
0 Karma
1 Solution

Drainy
Champion

Have a read of;
http://docs.splunk.com/Documentation/Splunk/latest/admin/HowSplunkstoresindexes#Troubleshoot_your_bu...

It sounds like you need to do a complete fsck of your buckets, this can take a few hours though depending on how big they are so set aside some time for it. It sounds like Splunk isn't being shut down cleanly or the servers are crashing out.

View solution in original post

Drainy
Champion

Have a read of;
http://docs.splunk.com/Documentation/Splunk/latest/admin/HowSplunkstoresindexes#Troubleshoot_your_bu...

It sounds like you need to do a complete fsck of your buckets, this can take a few hours though depending on how big they are so set aside some time for it. It sounds like Splunk isn't being shut down cleanly or the servers are crashing out.

krussell101
Path Finder

perfect! The page you reference suggests splunk fsck with the rebuild option.

I ran it with --repair --all on each server and that did the trick.

On several of the servers, there were no errors when splunk was started (before running fsck). So the only evidence of a problem was the log entry.

Interesting.

At any rate. Thanks very much for taking the time to help.

Much appreciated.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...