Splunk Enterprise

Splunk Stuck Checking Indexes when using Smart Store

luke10
Observer

I have a Splunk instance that is deployed on EBS Volume mounted to EC2 Instance.

I started working on enabling Smart Store for one of my indexes but whenever I have the indexes.conf configured to let one of my indexes use the smart store, when I restart splunk it basically hangs on this step:

Checking prerequisites...
Checking http port [8000]: open
Checking mgmt port [8089]: open
Checking appserver port [127.0.0.1:8065]: open
Checking kvstore port [8191]: open
Checking configuration... Done.
Checking critical directories... Done
Checking indexes...

 Nothing found in logs, I am just puzzled how to fix this. Can anybody hint what can be the issue?

indexes.conf:

[volume:s3volumeone]
storageType = remote
path = s3://some-bucket-name
remote.s3.endpoint = https://s3.us-west-2.amazonaws.com

[smart_store_index_10]
remotePath = volume:s3volumeone/$_index_name
homePath = $SPLUNK_DB/$_index_name/db
coldPath = $SPLUNK_DB/$_index_name/colddb
thawedPath = $SPLUNK_DB/$_index_name/thaweddb
maxGlobalDataSizeMB = 0
maxGlobalRawDataSizeMB = 0
homePath.maxDataSizeMB = 1000
maxHotBuckets = 2
maxDataSize = 3
maxWarmDBCount = 5
frozenTimePeriodInSecs = 10800

small numbers for bucket size etc. are intentional to allow quick testing of settings.

Labels (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Have you check that your IAM roles are still correctly defined and valid for your node? 
Can you run those S3 access test commands?

0 Karma

luke10
Observer

I am sorry but I don't see any commands. Did you mean to attach them to the post?

0 Karma

isoutamo
SplunkTrust
SplunkTrust
I didn’t add those to previous messages as answered by phone.
You could look those from https://docs.splunk.com/Documentation/Splunk/9.2.0/Indexer/TroubleshootSmartStore
0 Karma
Get Updates on the Splunk Community!

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...