Splunk Enterprise

When trying to fix corrupted buckets with gunzip journal.gz, why am I getting the following error? : "unexpected end of file".

tlabue
Path Finder

I am running Splunk v6.6.3. I've found corrupted buckets and have tried to fix via the:

splunk fsck repair --one-bucket --index-name=indextest--bucket-name=db_1502353482_1504459082_1 --try-warm-then-cold
command.

This failed for me on all the buckets. I tried to repair with the following error:

Error reading rawdata: Error reading compressed journal while streaming: gzip data truncated.

I also tried this method I saw in the Answers:
1. cd to bucket's rawdata directory
2. gunzip journal.gz (this will produce a journal file)
3. gzip -c journal > journal.gz (recompresses the journal file into journal.gz)
4. delete journal
5. Re-run the repair command above and restart the the splunk server.

However, the gunzip journal.gz command also failed with the following error: unexpected end of file.

Is there something else I can try to repair the corrupted journal.gz files?

Tags (2)
0 Karma

bstimely
New Member

I had the same problem and went down the same path using gunzip.
In the end it was not helpful. I was able to recover from the original bucket by using the exporttool.

Stop splunk of disable the index
mv corrupt directory to /tmp
splunk cmd exporttool -csv
splunk cmd importtool

mv the newbucketdirectory back into the db
restart splunk.

0 Karma
Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...