Splunk Enterprise

When trying to fix corrupted buckets with gunzip journal.gz, why am I getting the following error? : "unexpected end of file".

tlabue
Path Finder

I am running Splunk v6.6.3. I've found corrupted buckets and have tried to fix via the:

splunk fsck repair --one-bucket --index-name=indextest--bucket-name=db_1502353482_1504459082_1 --try-warm-then-cold
command.

This failed for me on all the buckets. I tried to repair with the following error:

Error reading rawdata: Error reading compressed journal while streaming: gzip data truncated.

I also tried this method I saw in the Answers:
1. cd to bucket's rawdata directory
2. gunzip journal.gz (this will produce a journal file)
3. gzip -c journal > journal.gz (recompresses the journal file into journal.gz)
4. delete journal
5. Re-run the repair command above and restart the the splunk server.

However, the gunzip journal.gz command also failed with the following error: unexpected end of file.

Is there something else I can try to repair the corrupted journal.gz files?

Tags (2)
0 Karma

bstimely
New Member

I had the same problem and went down the same path using gunzip.
In the end it was not helpful. I was able to recover from the original bucket by using the exporttool.

Stop splunk of disable the index
mv corrupt directory to /tmp
splunk cmd exporttool -csv
splunk cmd importtool

mv the newbucketdirectory back into the db
restart splunk.

0 Karma
Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...