Monitoring Splunk

Splunkd Service is in a restart loop

Yorkiedortmund
New Member

I am trying to start the Plunkd service but when i do it starts and stops with the below error

C:\Users\Administrator>net start splunkd service The Splunkd Service service is starting......
The Splunkd Service service could not be started.

A system error has occurred.

System error 1067 has occurred.

The process terminated unexpectedly.

These are the logs i see in the utility log.

03-25-2019 19:19:29.132 +0000 INFO loader - Running utility: "validatedb"
03-25-2019 19:19:29.132 +0000 INFO loader - Getting configuration data from: C:\Program Files\Splunk\etc\myinstall\splunkd.xml
03-25-2019 19:19:29.132 +0000 INFO loader - SPLUNK_MODULE_PATH environment variable not found - defaulting to C:\Program Files\Splunk\etc\modules
03-25-2019 19:19:29.132 +0000 INFO loader - loading modules from C:\Program Files\Splunk\etc\modules
03-25-2019 19:19:29.132 +0000 INFO loader - Writing out composite configuration file: C:\Program Files\Splunk\var\run\splunk\composite.xml
03-25-2019 19:19:29.178 +0000 INFO loader - Validated 22 indexes in 31.20 milliseconds
03-25-2019 19:19:29.522 +0000 INFO ServerConfig - Found no hostname options in server.conf. Will attempt to use default for now.
03-25-2019 19:19:29.522 +0000 INFO ServerConfig - Host name option is "".
03-25-2019 19:19:33.936 +0000 INFO loader - Running utility: "check-transforms-keys"
03-25-2019 19:19:33.952 +0000 INFO loader - Getting configuration data from: C:\Program Files\Splunk\etc\myinstall\splunkd.xml
03-25-2019 19:19:33.952 +0000 INFO loader - SPLUNK_MODULE_PATH environment variable not found - defaulting to C:\Program Files\Splunk\etc\modules
03-25-2019 19:19:33.952 +0000 INFO loader - loading modules from C:\Program Files\Splunk\etc\modules
03-25-2019 19:19:33.952 +0000 INFO loader - Writing out composite configuration file: C:\Program Files\Splunk\var\run\splunk\composite.xml

0 Karma

MuS
SplunkTrust
SplunkTrust

Have you checked $SPLUNK_HOME\var\log\splunk\splunkd.log for errors?
Try running in an admin CMD:
$SPLUNK_HOME\bin\splunk.exe clean locks
$SPLUNK_HOME\bin\splunk.exe restart

cheers, MuS

0 Karma

Yorkiedortmund
New Member

Hi

Thanks for your reply i found this error ref id conflicts . i cleaned the folders in the internal DB folder which had the same index and it worked.

03-25-2019 20:30:34.345 +0000 ERROR DatabaseDirectoryManager - idx=_internal bid=_internal~224~3939F5CA-24AC-4784-A8F5-E7A643522CC1 bucket=db_1550770768_1550338769_224 Detected directory manually copied into its database, causing id conflicts [path1='C:\Program Files\Splunk\var\lib\splunk_internaldb\db\db_1550601271_1550338769_224' path2='C:\Program Files\Splunk\var\lib\splunk_internaldb\db\db_1550770768_1550338769_224'].

0 Karma
Get Updates on the Splunk Community!

Security Highlights: September 2022 Newsletter

 September 2022 The Splunk App for Fraud Analytics (SFA) is now Splunk SupportedUse your existing Splunk ...

Platform Highlights | September 2022 Newsletter

 September 2022 What’s New in 9.0 and How to UpgradeGet a walk through of what is new Splunk Enterprise 9.0 ...

Observability Highlights | September 2022 Newsletter

 September 2022 Splunk Observability SuiteAccess to "Classic" SignalFx Interface Will be Removed on Sept 30, ...