Getting Data In

"Indexer was started dirty"

krussell101
Path Finder

I have no clue what this error means.

The entire error in the splunkd.log is:

Indexer was started dirty, searches may not be accurate. Consider restarting Splunk and accepting the recovery request.

When I stop and restart splunk I'm not offered a recovery option.

I am getting these on virtually every server where I'm running splunk. Heavy forwarders and the indexer itself. The only exception are the two servers where I am running universal forwarders.

What does it mean and how do I clear it?

Thanks!!!

Tags (1)
0 Karma
1 Solution

Drainy
Champion

Have a read of;
http://docs.splunk.com/Documentation/Splunk/latest/admin/HowSplunkstoresindexes#Troubleshoot_your_bu...

It sounds like you need to do a complete fsck of your buckets, this can take a few hours though depending on how big they are so set aside some time for it. It sounds like Splunk isn't being shut down cleanly or the servers are crashing out.

View solution in original post

Drainy
Champion

Have a read of;
http://docs.splunk.com/Documentation/Splunk/latest/admin/HowSplunkstoresindexes#Troubleshoot_your_bu...

It sounds like you need to do a complete fsck of your buckets, this can take a few hours though depending on how big they are so set aside some time for it. It sounds like Splunk isn't being shut down cleanly or the servers are crashing out.

krussell101
Path Finder

perfect! The page you reference suggests splunk fsck with the rebuild option.

I ran it with --repair --all on each server and that did the trick.

On several of the servers, there were no errors when splunk was started (before running fsck). So the only evidence of a problem was the log entry.

Interesting.

At any rate. Thanks very much for taking the time to help.

Much appreciated.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...