Monitoring Splunk

During startup recovery, error reading from process runner child: Bad file number. Splunk fsck failed with error code '8'.

zliu
Splunk Employee
Splunk Employee

When startup and recovering from a unclean shutdown.
Perform recovery now? [y/n] y
Recovering (across all data)...
Error reading from process runner child: Bad file number
Splunk fsck failed with error code '8'. Please file a case online at http://www.splunk.com/page/submit_issue

running splunk as a heavy forwarder without indexing on a some AIX systems with a non root user called splkadm.

Splunk 4.2.1

Tags (1)
1 Solution

Rob
Splunk Employee
Splunk Employee

This is an issue specific to AIX causing the fsck utility to fail.

If you do not wish to see this error you may wish to delete the meta.dirty file that is located in the $SPLUNK_HOME/var/lib/splunk/defaultdb/db/ directory.

Keep in mind that this will only delete the file that was generated on an unclean shutdown and does not actually repair the buckets. To do so you may wish to run the fsck utility manually with the following command:

$SPLUNK_HOME/bin/splunk cmd splunkd fsck --all --mode metadata --repair

Otherwise, have a look at the following answer which describes how to validate the metadata files as well as the bucket tsidx files.

http://splunk-base.splunk.com/answers/5374/how-to-quickly-validate-the-metadata-files-of-a-given-ind...

View solution in original post

Rob
Splunk Employee
Splunk Employee

This is an issue specific to AIX causing the fsck utility to fail.

If you do not wish to see this error you may wish to delete the meta.dirty file that is located in the $SPLUNK_HOME/var/lib/splunk/defaultdb/db/ directory.

Keep in mind that this will only delete the file that was generated on an unclean shutdown and does not actually repair the buckets. To do so you may wish to run the fsck utility manually with the following command:

$SPLUNK_HOME/bin/splunk cmd splunkd fsck --all --mode metadata --repair

Otherwise, have a look at the following answer which describes how to validate the metadata files as well as the bucket tsidx files.

http://splunk-base.splunk.com/answers/5374/how-to-quickly-validate-the-metadata-files-of-a-given-ind...

zliu
Splunk Employee
Splunk Employee

It could be caused by Splunk on AIX 6.x.
Splunk is not certified to work on AIX 6.x.

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...