Monitoring Splunk

Splunkd Service is in a restart loop

Yorkiedortmund
New Member

I am trying to start the Plunkd service but when i do it starts and stops with the below error

C:\Users\Administrator>net start splunkd service The Splunkd Service service is starting......
The Splunkd Service service could not be started.

A system error has occurred.

System error 1067 has occurred.

The process terminated unexpectedly.

These are the logs i see in the utility log.

03-25-2019 19:19:29.132 +0000 INFO loader - Running utility: "validatedb"
03-25-2019 19:19:29.132 +0000 INFO loader - Getting configuration data from: C:\Program Files\Splunk\etc\myinstall\splunkd.xml
03-25-2019 19:19:29.132 +0000 INFO loader - SPLUNK_MODULE_PATH environment variable not found - defaulting to C:\Program Files\Splunk\etc\modules
03-25-2019 19:19:29.132 +0000 INFO loader - loading modules from C:\Program Files\Splunk\etc\modules
03-25-2019 19:19:29.132 +0000 INFO loader - Writing out composite configuration file: C:\Program Files\Splunk\var\run\splunk\composite.xml
03-25-2019 19:19:29.178 +0000 INFO loader - Validated 22 indexes in 31.20 milliseconds
03-25-2019 19:19:29.522 +0000 INFO ServerConfig - Found no hostname options in server.conf. Will attempt to use default for now.
03-25-2019 19:19:29.522 +0000 INFO ServerConfig - Host name option is "".
03-25-2019 19:19:33.936 +0000 INFO loader - Running utility: "check-transforms-keys"
03-25-2019 19:19:33.952 +0000 INFO loader - Getting configuration data from: C:\Program Files\Splunk\etc\myinstall\splunkd.xml
03-25-2019 19:19:33.952 +0000 INFO loader - SPLUNK_MODULE_PATH environment variable not found - defaulting to C:\Program Files\Splunk\etc\modules
03-25-2019 19:19:33.952 +0000 INFO loader - loading modules from C:\Program Files\Splunk\etc\modules
03-25-2019 19:19:33.952 +0000 INFO loader - Writing out composite configuration file: C:\Program Files\Splunk\var\run\splunk\composite.xml

0 Karma

MuS
Legend

Have you checked $SPLUNK_HOME\var\log\splunk\splunkd.log for errors?
Try running in an admin CMD:
$SPLUNK_HOME\bin\splunk.exe clean locks
$SPLUNK_HOME\bin\splunk.exe restart

cheers, MuS

0 Karma

Yorkiedortmund
New Member

Hi

Thanks for your reply i found this error ref id conflicts . i cleaned the folders in the internal DB folder which had the same index and it worked.

03-25-2019 20:30:34.345 +0000 ERROR DatabaseDirectoryManager - idx=_internal bid=_internal~224~3939F5CA-24AC-4784-A8F5-E7A643522CC1 bucket=db_1550770768_1550338769_224 Detected directory manually copied into its database, causing id conflicts [path1='C:\Program Files\Splunk\var\lib\splunk_internaldb\db\db_1550601271_1550338769_224' path2='C:\Program Files\Splunk\var\lib\splunk_internaldb\db\db_1550770768_1550338769_224'].

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...