Getting Data In

splunk upgrade from 7.3.3 to 8.0.0 failed (Could not create path D:\splunk\data\index\_metrics\db appearing in indexes.conf: 5 )

jerjer951109
Loves-to-Learn

Hi, anyone know how to solve this problem?

C:\Users\AppData\Local\temp\splunk.log
In the log file is shown :

Could not create path D:\splunk\data\index_metrics\db appearing in indexes.conf: 5
Validating databases (splunk valiadated) failed with code '1'

as we have tried to use Admin account already and can access to this folder D:\splunk\data\index\_metrics.
but we cannot upgrade successfully.

system environment:
Splunk 7.3.3
Windows Server 2012 R2

Tags (3)
0 Karma

woodcock
Esteemed Legend

This is a permissions problem: Splunk cannot create that directory and it MUST in order to run. You can either manually create or give the user that Splunk is running as the permission to create it.

0 Karma

MaverickT
Communicator

Hi,

can you check under which user splunk service is running? By default it is system. This user also needs to have read/write/execute permission on the folder D:\splunk\data\index_metrics\

Just a friendly tip: I suggest you migrate your splunk environment to linux. Since we have done it, our life is much easier.

0 Karma

jerjer951109
Loves-to-Learn

Do you know which user for D:\splunk\data\index\_metrics\?
As currently, we cannot see the owner.

https://imgur.com/ru47Xw8
https://imgur.com/ru47Xw8
https://imgur.com/Wxxa6Rw

0 Karma

jerjer951109
Loves-to-Learn

system user is running splunkd service.
For D:\splunk\data\index\_metrics\, it is read only and it shows that You do not have permission to view this object's security properties, even as an administrator user.

0 Karma

MaverickT
Communicator

@jerjer951109 I see that can be your problem... Try taking over ownership of the folder with your admin account and then you will be able to change the permissions.

0 Karma

jhornsby_splunk
Splunk Employee
Splunk Employee

Hi @jerjer951109 ,

Where are you seeing that message?

Cheers,

- Jo.

0 Karma

jerjer951109
Loves-to-Learn

C:\Users\AppData\Local\temp\splunk.log

0 Karma

jerjer951109
Loves-to-Learn

i upgrade using splunk-8.0.0-x64.msi but failed
then i checked log C:\Users\AppData\Local\temp\splunk.log and see this error

0 Karma

jerjer951109
Loves-to-Learn

OS: Windows server 2012

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...