Monitoring Splunk

Splunkd Service is in a restart loop

Yorkiedortmund
New Member

I am trying to start the Plunkd service but when i do it starts and stops with the below error

C:\Users\Administrator>net start splunkd service The Splunkd Service service is starting......
The Splunkd Service service could not be started.

A system error has occurred.

System error 1067 has occurred.

The process terminated unexpectedly.

These are the logs i see in the utility log.

03-25-2019 19:19:29.132 +0000 INFO loader - Running utility: "validatedb"
03-25-2019 19:19:29.132 +0000 INFO loader - Getting configuration data from: C:\Program Files\Splunk\etc\myinstall\splunkd.xml
03-25-2019 19:19:29.132 +0000 INFO loader - SPLUNK_MODULE_PATH environment variable not found - defaulting to C:\Program Files\Splunk\etc\modules
03-25-2019 19:19:29.132 +0000 INFO loader - loading modules from C:\Program Files\Splunk\etc\modules
03-25-2019 19:19:29.132 +0000 INFO loader - Writing out composite configuration file: C:\Program Files\Splunk\var\run\splunk\composite.xml
03-25-2019 19:19:29.178 +0000 INFO loader - Validated 22 indexes in 31.20 milliseconds
03-25-2019 19:19:29.522 +0000 INFO ServerConfig - Found no hostname options in server.conf. Will attempt to use default for now.
03-25-2019 19:19:29.522 +0000 INFO ServerConfig - Host name option is "".
03-25-2019 19:19:33.936 +0000 INFO loader - Running utility: "check-transforms-keys"
03-25-2019 19:19:33.952 +0000 INFO loader - Getting configuration data from: C:\Program Files\Splunk\etc\myinstall\splunkd.xml
03-25-2019 19:19:33.952 +0000 INFO loader - SPLUNK_MODULE_PATH environment variable not found - defaulting to C:\Program Files\Splunk\etc\modules
03-25-2019 19:19:33.952 +0000 INFO loader - loading modules from C:\Program Files\Splunk\etc\modules
03-25-2019 19:19:33.952 +0000 INFO loader - Writing out composite configuration file: C:\Program Files\Splunk\var\run\splunk\composite.xml

0 Karma

MuS
SplunkTrust
SplunkTrust

Have you checked $SPLUNK_HOME\var\log\splunk\splunkd.log for errors?
Try running in an admin CMD:
$SPLUNK_HOME\bin\splunk.exe clean locks
$SPLUNK_HOME\bin\splunk.exe restart

cheers, MuS

0 Karma

Yorkiedortmund
New Member

Hi

Thanks for your reply i found this error ref id conflicts . i cleaned the folders in the internal DB folder which had the same index and it worked.

03-25-2019 20:30:34.345 +0000 ERROR DatabaseDirectoryManager - idx=_internal bid=_internal~224~3939F5CA-24AC-4784-A8F5-E7A643522CC1 bucket=db_1550770768_1550338769_224 Detected directory manually copied into its database, causing id conflicts [path1='C:\Program Files\Splunk\var\lib\splunk_internaldb\db\db_1550601271_1550338769_224' path2='C:\Program Files\Splunk\var\lib\splunk_internaldb\db\db_1550770768_1550338769_224'].

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...