Monitoring Splunk

Splunkd Service is in a restart loop

Yorkiedortmund
New Member

I am trying to start the Plunkd service but when i do it starts and stops with the below error

C:\Users\Administrator>net start splunkd service The Splunkd Service service is starting......
The Splunkd Service service could not be started.

A system error has occurred.

System error 1067 has occurred.

The process terminated unexpectedly.

These are the logs i see in the utility log.

03-25-2019 19:19:29.132 +0000 INFO loader - Running utility: "validatedb"
03-25-2019 19:19:29.132 +0000 INFO loader - Getting configuration data from: C:\Program Files\Splunk\etc\myinstall\splunkd.xml
03-25-2019 19:19:29.132 +0000 INFO loader - SPLUNK_MODULE_PATH environment variable not found - defaulting to C:\Program Files\Splunk\etc\modules
03-25-2019 19:19:29.132 +0000 INFO loader - loading modules from C:\Program Files\Splunk\etc\modules
03-25-2019 19:19:29.132 +0000 INFO loader - Writing out composite configuration file: C:\Program Files\Splunk\var\run\splunk\composite.xml
03-25-2019 19:19:29.178 +0000 INFO loader - Validated 22 indexes in 31.20 milliseconds
03-25-2019 19:19:29.522 +0000 INFO ServerConfig - Found no hostname options in server.conf. Will attempt to use default for now.
03-25-2019 19:19:29.522 +0000 INFO ServerConfig - Host name option is "".
03-25-2019 19:19:33.936 +0000 INFO loader - Running utility: "check-transforms-keys"
03-25-2019 19:19:33.952 +0000 INFO loader - Getting configuration data from: C:\Program Files\Splunk\etc\myinstall\splunkd.xml
03-25-2019 19:19:33.952 +0000 INFO loader - SPLUNK_MODULE_PATH environment variable not found - defaulting to C:\Program Files\Splunk\etc\modules
03-25-2019 19:19:33.952 +0000 INFO loader - loading modules from C:\Program Files\Splunk\etc\modules
03-25-2019 19:19:33.952 +0000 INFO loader - Writing out composite configuration file: C:\Program Files\Splunk\var\run\splunk\composite.xml

0 Karma

MuS
Legend

Have you checked $SPLUNK_HOME\var\log\splunk\splunkd.log for errors?
Try running in an admin CMD:
$SPLUNK_HOME\bin\splunk.exe clean locks
$SPLUNK_HOME\bin\splunk.exe restart

cheers, MuS

0 Karma

Yorkiedortmund
New Member

Hi

Thanks for your reply i found this error ref id conflicts . i cleaned the folders in the internal DB folder which had the same index and it worked.

03-25-2019 20:30:34.345 +0000 ERROR DatabaseDirectoryManager - idx=_internal bid=_internal~224~3939F5CA-24AC-4784-A8F5-E7A643522CC1 bucket=db_1550770768_1550338769_224 Detected directory manually copied into its database, causing id conflicts [path1='C:\Program Files\Splunk\var\lib\splunk_internaldb\db\db_1550601271_1550338769_224' path2='C:\Program Files\Splunk\var\lib\splunk_internaldb\db\db_1550770768_1550338769_224'].

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...