Getting Data In

splunk upgrade from 7.3.3 to 8.0.0 failed (Could not create path D:\splunk\data\index\_metrics\db appearing in indexes.conf: 5 )

jerjer951109
Loves-to-Learn

Hi, anyone know how to solve this problem?

C:\Users\AppData\Local\temp\splunk.log
In the log file is shown :

Could not create path D:\splunk\data\index_metrics\db appearing in indexes.conf: 5
Validating databases (splunk valiadated) failed with code '1'

as we have tried to use Admin account already and can access to this folder D:\splunk\data\index\_metrics.
but we cannot upgrade successfully.

system environment:
Splunk 7.3.3
Windows Server 2012 R2

Tags (3)
0 Karma

woodcock
Esteemed Legend

This is a permissions problem: Splunk cannot create that directory and it MUST in order to run. You can either manually create or give the user that Splunk is running as the permission to create it.

0 Karma

MaverickT
Communicator

Hi,

can you check under which user splunk service is running? By default it is system. This user also needs to have read/write/execute permission on the folder D:\splunk\data\index_metrics\

Just a friendly tip: I suggest you migrate your splunk environment to linux. Since we have done it, our life is much easier.

0 Karma

jerjer951109
Loves-to-Learn

Do you know which user for D:\splunk\data\index\_metrics\?
As currently, we cannot see the owner.

https://imgur.com/ru47Xw8
https://imgur.com/ru47Xw8
https://imgur.com/Wxxa6Rw

0 Karma

jerjer951109
Loves-to-Learn

system user is running splunkd service.
For D:\splunk\data\index\_metrics\, it is read only and it shows that You do not have permission to view this object's security properties, even as an administrator user.

0 Karma

MaverickT
Communicator

@jerjer951109 I see that can be your problem... Try taking over ownership of the folder with your admin account and then you will be able to change the permissions.

0 Karma

jhornsby_splunk
Splunk Employee
Splunk Employee

Hi @jerjer951109 ,

Where are you seeing that message?

Cheers,

- Jo.

0 Karma

jerjer951109
Loves-to-Learn

C:\Users\AppData\Local\temp\splunk.log

0 Karma

jerjer951109
Loves-to-Learn

i upgrade using splunk-8.0.0-x64.msi but failed
then i checked log C:\Users\AppData\Local\temp\splunk.log and see this error

0 Karma

jerjer951109
Loves-to-Learn

OS: Windows server 2012

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...