I'm not sure if this is the issue or not, but I think that Spotlight is attempting to index the hot_db and the errors are filling up my /var/log/system.log file.
This is the error file I'm seeing in system.log:
Oct 6 16:16:15 hostname.local mds: (/.Spotlight-V100/Store-V2/19A22DF0-5F1D-4B5D-837C-DF34BA911F38)(Error) IndexPath in oid_t _oidParentForOid(SIPersistentIDStoreRef, uint64_t):stat succeeded, getattrlist returned error 2 for 18980198 (/.vol/16777218/18980198 = /Applications/splunk/var/lib/splunk/defaultdb/db/hot_v1_27/1381090574-1381090574-16724175646614228905.pre-tsidx)
The "returned error 2 for #" are changing as they continue.
When I start Splunk, it says that there were problems with the configuration file, do I want to continue. If I select "Yes", Splunk starts as normal, but I see the above errors. If I select "No", it doesn't start and tells me that there were Parsing Errors in the "configuration file"...I don't think its related, but it could be some context?
Checking configuration... Error while parsing '/Applications/splunk/etc/apps/sentiment/default/data/ui/views/home.xml':
no element found: line 3, column 0