Monitoring Splunk
Highlighted

Splunk Daemon Crashing

New Member

Just downloaded Splunk 4.1.3 for windows 32 bit. Running Windows 7 32 bit Enterprise Edition.

This is what I am getting in my log -- any idea how to fix it? "ERROR WordPositionData - couldn't parse hash code:"

More from the splunkd.log:


06-15-2010 11:44:16.832 INFO  loader - Splunkd starting (build 80534).
06-15-2010 11:44:16.832 INFO  loader - System info: Windows, CFALZONE, 1, 6, Intel.
06-15-2010 11:44:16.832 INFO  loader - Detected 2 (virtual) CPUs and 2814MB RAM
06-15-2010 11:44:16.832 INFO  loader - Getting configuration data from: C:\Program Files\Splunk\etc\myinstall\splunkd.xml
06-15-2010 11:44:16.833 INFO  loader - SPLUNK_MODULE_PATH environment variable not found - defaulting to C:\Program Files\Splunk\etc\modules
06-15-2010 11:44:16.833 INFO  loader - loading modules from C:\Program Files\Splunk\etc\modules
06-15-2010 11:44:16.834 INFO  loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\distributedDeployment
06-15-2010 11:44:16.834 INFO  loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\distributedDeployment\classes
06-15-2010 11:44:16.834 INFO  loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\distributedDeployment\classes\deployable
06-15-2010 11:44:16.834 INFO  loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\distributedDeployment\classes\deploymentserver
06-15-2010 11:44:16.835 INFO  loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\input
06-15-2010 11:44:16.836 INFO  loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\input\TCP
06-15-2010 11:44:16.837 INFO  loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\input\UDP
06-15-2010 11:44:16.837 INFO  loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\input\exec
06-15-2010 11:44:16.838 INFO  loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\input\fschangemanager
06-15-2010 11:44:16.839 INFO  loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\input\log4jTCP
06-15-2010 11:44:16.839 INFO  loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\input\splunkTCP
06-15-2010 11:44:16.839 INFO  loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\input\syslogUDP
06-15-2010 11:44:16.839 INFO  loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\input\tailfile
06-15-2010 11:44:16.841 INFO  loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\input\wineventlog
06-15-2010 11:44:16.842 INFO  loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\internal
06-15-2010 11:44:16.842 INFO  loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\internal\scheduler
06-15-2010 11:44:16.842 INFO  loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\parsing
06-15-2010 11:44:16.844 INFO  loader - Writing out composite configuration file: C:\Program Files\Splunk\var\run\splunk\composite.xml
06-15-2010 11:44:16.892 INFO  LicenseManager - Initializing
06-15-2010 11:44:16.918 INFO  LicenseManager - Looking for bytequotaprocessor...
06-15-2010 11:44:16.918 INFO  LicenseManager - Checking for previous keyed license
06-15-2010 11:44:17.451 INFO  LicenseManager - Using 5 for MAX VIOLATIONS
06-15-2010 11:44:17.451 INFO  LicenseManager - Using 30 for VIOLATION PERIOD (days)
06-15-2010 11:44:17.460 INFO  IndexProcessor - running splunkd specific init
06-15-2010 11:44:17.470 INFO  ServerConfig - My server name is "CFALZONE".
06-15-2010 11:44:17.470 INFO  ServerConfig - Default output queue for file-based input: parsingQueue.
06-15-2010 11:44:17.481 INFO  loader - Initializing from configuration
06-15-2010 11:44:17.483 INFO  PipelineComponent - Pipeline indexerPipe enabled
06-15-2010 11:44:17.483 INFO  loader - Instantiated plugin: queueinputprocessor
06-15-2010 11:44:17.483 INFO  loader - Instantiated plugin: tcpoutputprocessor
06-15-2010 11:44:17.496 INFO  loader - Instantiated plugin: syslogoutputprocessor
06-15-2010 11:44:17.519 INFO  loader - Instantiated plugin: httpoutputprocessor
06-15-2010 11:44:17.542 INFO  loader - Instantiated plugin: indexandforwardprocessor
06-15-2010 11:44:17.565 INFO  loader - Instantiated plugin: bytequotaprocessor
06-15-2010 11:44:17.565 INFO  loader - Instantiated plugin: signingprocessor
06-15-2010 11:44:17.565 INFO  loader - Instantiated plugin: indexprocessor
06-15-2010 11:44:17.565 INFO  IndexProcessor - initializing with fullInit=true
06-15-2010 11:44:17.568 INFO  IndexProcessor - indexes.conf - indexThreads param autotuned to 2
06-15-2010 11:44:17.568 INFO  TPool - initializing IndexerTPool with 2 workers
06-15-2010 11:44:17.568 INFO  IndexProcessor - indexes.conf - memPoolMB param autotuned to 256MB
06-15-2010 11:44:17.568 INFO  MPool - MPool initialized: bytes=268435456 
06-15-2010 11:44:17.569 INFO  HotDBManager - creating hot mgr: C:\Program Files\Splunk\var\lib\splunk\audit\db maxHotSpanSecs=7776000 maxHotBuckets=1 maxDataSizeBytes=786432000 quarantinePastSecs=77760000 quarantineFutureSecs=2592000 
06-15-2010 11:44:17.569 INFO  databasePartitionPolicy - index _audit initialized with [300,60,188697600,,,786432000,20,500000,5,5,false,3,0,_blocksignature,7776000,0,1,77760000,2592000,10485760]
06-15-2010 11:44:17.569 INFO  databasePartitionPolicy - openDatabase for C:\Program Files\Splunk\var\lib\splunk\audit\db
06-15-2010 11:44:17.571 INFO  BucketMover - initiatializing BucketMoverTPool
06-15-2010 11:44:17.571 INFO  TPool - initializing BucketMoverTPool with 5 workers
06-15-2010 11:44:17.572 INFO  databasePartitionPolicy - We are running on a pre-existing database opening ...
06-15-2010 11:44:17.572 INFO  databasePartitionPolicy - Found timestamp file ! at C:\Program Files\Splunk\var\lib\splunk\audit\db\CreationTime
06-15-2010 11:44:17.574 INFO  databasePartitionPolicy - CREATION TIME for C:\Program Files\Splunk\var\lib\splunk\audit\db : 1274814326
06-15-2010 11:44:17.574 INFO  databasePartitionPolicy - opening database C:\Program Files\Splunk\var\lib\splunk\audit\db\hot_v1_0
06-15-2010 11:44:17.574 INFO  timeinvertedIndex - Opening C:\Program Files\Splunk\var\lib\splunk\audit\db\hot_v1_0
06-15-2010 11:44:17.574 INFO  timeinvertedIndex - No files to decompress on create
06-15-2010 11:44:17.574 INFO  timeinvertedIndex - create by dirname C:\Program Files\Splunk\var\lib\splunk\audit\db\hot_v1_0
06-15-2010 11:44:17.576 INFO  databasePartitionPolicy - found hot db with 20813 events
06-15-2010 11:44:17.576 INFO  HotDBManager - recovered hot: hot_v1_0, [id=0, et=1274814325, lt=1275067822]
06-15-2010 11:44:17.581 INFO  databasePartitionPolicy - currentId for C:\Program Files\Splunk\var\lib\splunk\audit\db after openDatabases = 1
06-15-2010 11:44:17.581 INFO  HotDBManager - creating hot mgr: C:\Program Files\Splunk\var\lib\splunk\blockSignature\db maxHotSpanSecs=7776000 maxHotBuckets=1 maxDataSizeBytes=1048576000 quarantinePastSecs=77760000 quarantineFutureSecs=2592000 
06-15-2010 11:44:17.581 INFO  databasePartitionPolicy - index _blocksignature initialized with [300,60,0,,,1048576000,20,0,5,5,false,3,0,_blocksignature,7776000,0,1,77760000,2592000,10485760]
06-15-2010 11:44:17.581 INFO  databasePartitionPolicy - openDatabase for C:\Program Files\Splunk\var\lib\splunk\blockSignature\db
06-15-2010 11:44:17.583 INFO  databasePartitionPolicy - We are running on a pre-existing database opening ...
06-15-2010 11:44:17.583 INFO  databasePartitionPolicy - No databases found starting fresh !
06-15-2010 11:44:17.584 INFO  databasePartitionPolicy - CREATION TIME for C:\Program Files\Splunk\var\lib\splunk\blockSignature\db : 1274814326
06-15-2010 11:44:17.585 INFO  databasePartitionPolicy - currentId for C:\Program Files\Splunk\var\lib\splunk\blockSignature\db after openDatabases = 0
06-15-2010 11:44:17.585 INFO  HotDBManager - creating hot mgr: C:\Program Files\Splunk\var\lib\splunk\_internaldb\db maxHotSpanSecs=7776000 maxHotBuckets=1 maxDataSizeBytes=104857600 quarantinePastSecs=77760000 quarantineFutureSecs=2592000 
06-15-2010 11:44:17.585 INFO  databasePartitionPolicy - index _internal initialized with [300,60,2419200,,,104857600,20,500000,5,5,false,3,0,_blocksignature,7776000,0,1,77760000,2592000,10485760]
06-15-2010 11:44:17.585 INFO  databasePartitionPolicy - openDatabase for C:\Program Files\Splunk\var\lib\splunk\_internaldb\db
06-15-2010 11:44:17.586 ERROR WordPositionData - couldn't parse hash code: 
Tags (1)
0 Karma
Highlighted

Re: Splunk Daemon Crashing

Super Champion

Have you tried contacting splunk support?

0 Karma
Highlighted

Re: Splunk Daemon Crashing

New Member

can i get infonon my friends computer by having her computer info and serial # and her location?

0 Karma