Monitoring Splunk

splunk clean eventdata crashes splunk.exe

helge
Builder

I am executing the following command on a Windows Server 2012 R2 machine with Splunk 6.0.1:

C:\Program Files\Splunk\bin>splunk clean eventdata -index INDEXNAME

This crashes splunk.exe. Windows displays a dialog box with the following information:

Problem signature:
  Problem Event Name:   APPCRASH
  Application Name: splunk.exe
  Application Version:  1536.256.0.58811
  Application Timestamp:    52ab7b46
  Fault Module Name:    splunk.exe
  Fault Module Version: 1536.256.0.58811
  Fault Module Timestamp:   52ab7b46
  Exception Code:   c0000005
  Exception Offset: 00000000000082c0
  OS Version:   6.3.9600.2.0.0.272.7
  Locale ID:    1031
  Additional Information 1: 1cf6
  Additional Information 2: 1cf651e9a88f0329c96cc649ff046e69
  Additional Information 3: 2fc5
  Additional Information 4: 2fc5f68b35a04306c3885ae9727075a7

Splunkd is stopped while I do that, of course.

Tags (2)

aderusha
Engager

I'm also seeing the same behavior on Server 2012 (non-R2). This is in an Administrator command window.

I had a server spew some 18 million syslog entries that I'd like to clear out and cannot do so due to this issue.

0 Karma

mss_recommind
Engager

Same problem here on Win2k8 R2 x64.

0 Karma

mss_recommind
Engager

yes and yes. still fails with the crash message from the OP above.

lukejadamec
Super Champion

I've cleaned indexes on W2K8R2 systems many times. Are you running the command from a cmd window that was started with 'run as administrator', and does the administrator have access to the index directories?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...