Security

having hundreds of sqlitePersistentStorageImp errors in splunkd logs

univofmem
Engager

04-01-2016 06:55:15.159 -0500 ERROR SQLitePersistentStorageImpl - Error processing enumerate: database disk image is malformed
04-01-2016 06:55:16.538 -0500 ERROR FSChangeMonitor - Exception thrown in update(2) - continuing

This happened after server crashed due to raid card error

Tags (1)
0 Karma
1 Solution

rmorlen_splunk
Splunk Employee
Splunk Employee

To correct this, browse to /opt/splunk/var/lib/splunk/persistentstorage/fschangemanager_state/ and in that directory, there is also a file called "fschangemanager_state". Rename that file or move it to a temporary location and then restart Splunk.

View solution in original post

rmorlen_splunk
Splunk Employee
Splunk Employee

To correct this, browse to /opt/splunk/var/lib/splunk/persistentstorage/fschangemanager_state/ and in that directory, there is also a file called "fschangemanager_state". Rename that file or move it to a temporary location and then restart Splunk.

univofmem
Engager

Thanks..Fixed it.

0 Karma

brent_weaver
Builder

I am seeing this error on a system with a UF, does this process need to be done on the UF or the splunk server. If splunk server, which server in a distributed env?

0 Karma

rmorlen_splunk
Splunk Employee
Splunk Employee

This would be on the server running the UF since it is doing the monitoring.

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...