I installed Splunk 7.0. When I click start Splunk, in the terminal I have the following error:
Splunk> Another one.
Checking http port : open
Checking mgmt port : open
Checking appserver port [127.0.0.1:8065]: open
Checking kvstore port : open
Checking configuration... Done.
Checking critical directories... Done
homePath='/Applications/Splunk/var/lib/splunk/audit/db' of index=audit on unusable filesystem.
Validating databases (splunkd validatedb) failed with code '1'. If you cannot resolve the issue(s) above after consulting documentation, please file a case online at http://www.splunk.com/page/submitissue
When can I find the documentation to fix this error?
Ive seen this before on my own machine:
You'll want to append the following configuration option to
OPTIMISTIC_ABOUT_FILE_LOCKING = 1
Then restart Splunk and it should start without any issues. Let me know how it goes!
Its also worth noting that Support for ALL versions of Splunk software on macOS 10.13 High Sierra has been REVOKED as of 23 Feb 2018.
Yes. Note that If you are concerned about your data in any way then you should not configure this bypass. This variable basically drops all filesystem lock checks and any data you store might or might not be retrievable.
Hi, I am trying to gain some hands-on learning of splunk on my mac (version 10.13.4, installed splunk 7.0.3). But based on related threads it seems to be a risky option for users.
1) is it safe to try setting the OPTIMISTICABOUTFILE_LOCKING = 1 configuration ?
2) in case data loss occurs on my system due to this, how do I go back to the previous setting ?
I did read in one of the answers that "There is work scheduled to fix the error for macOS 10.13" - any update on this ?
Update: This is fixed in the Splunk Enterprise 7.1 release. The fix will also appear in a future 7.0.x maintenance release.