Monitoring Splunk

Splunkd Service is in a restart loop

Yorkiedortmund
New Member

I am trying to start the Plunkd service but when i do it starts and stops with the below error

C:\Users\Administrator>net start splunkd service The Splunkd Service service is starting......
The Splunkd Service service could not be started.

A system error has occurred.

System error 1067 has occurred.

The process terminated unexpectedly.

These are the logs i see in the utility log.

03-25-2019 19:19:29.132 +0000 INFO loader - Running utility: "validatedb"
03-25-2019 19:19:29.132 +0000 INFO loader - Getting configuration data from: C:\Program Files\Splunk\etc\myinstall\splunkd.xml
03-25-2019 19:19:29.132 +0000 INFO loader - SPLUNK_MODULE_PATH environment variable not found - defaulting to C:\Program Files\Splunk\etc\modules
03-25-2019 19:19:29.132 +0000 INFO loader - loading modules from C:\Program Files\Splunk\etc\modules
03-25-2019 19:19:29.132 +0000 INFO loader - Writing out composite configuration file: C:\Program Files\Splunk\var\run\splunk\composite.xml
03-25-2019 19:19:29.178 +0000 INFO loader - Validated 22 indexes in 31.20 milliseconds
03-25-2019 19:19:29.522 +0000 INFO ServerConfig - Found no hostname options in server.conf. Will attempt to use default for now.
03-25-2019 19:19:29.522 +0000 INFO ServerConfig - Host name option is "".
03-25-2019 19:19:33.936 +0000 INFO loader - Running utility: "check-transforms-keys"
03-25-2019 19:19:33.952 +0000 INFO loader - Getting configuration data from: C:\Program Files\Splunk\etc\myinstall\splunkd.xml
03-25-2019 19:19:33.952 +0000 INFO loader - SPLUNK_MODULE_PATH environment variable not found - defaulting to C:\Program Files\Splunk\etc\modules
03-25-2019 19:19:33.952 +0000 INFO loader - loading modules from C:\Program Files\Splunk\etc\modules
03-25-2019 19:19:33.952 +0000 INFO loader - Writing out composite configuration file: C:\Program Files\Splunk\var\run\splunk\composite.xml

0 Karma

MuS
SplunkTrust
SplunkTrust

Have you checked $SPLUNK_HOME\var\log\splunk\splunkd.log for errors?
Try running in an admin CMD:
$SPLUNK_HOME\bin\splunk.exe clean locks
$SPLUNK_HOME\bin\splunk.exe restart

cheers, MuS

0 Karma

Yorkiedortmund
New Member

Hi

Thanks for your reply i found this error ref id conflicts . i cleaned the folders in the internal DB folder which had the same index and it worked.

03-25-2019 20:30:34.345 +0000 ERROR DatabaseDirectoryManager - idx=_internal bid=_internal~224~3939F5CA-24AC-4784-A8F5-E7A643522CC1 bucket=db_1550770768_1550338769_224 Detected directory manually copied into its database, causing id conflicts [path1='C:\Program Files\Splunk\var\lib\splunk_internaldb\db\db_1550601271_1550338769_224' path2='C:\Program Files\Splunk\var\lib\splunk_internaldb\db\db_1550770768_1550338769_224'].

0 Karma
Get Updates on the Splunk Community!

New Learning Videos on Topics Most Requested by You! Plus This Month’s New Splunk ...

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

How I Instrumented a Rust Application Without Knowing Rust

As a technical writer, I often have to edit or create code snippets for Splunk's distributions of ...

Splunk Community Platform Survey

Hey Splunk Community, Starting today, the community platform may prompt you to participate in a survey. The ...