Splunk Search

Help! Summary search process stuck ?

the_wolverine
Champion

I started running the fill_summary_index.py script and my session was interrupted. The summary backfill process never completed and I'm unable to restart it. I've tried restarting Splunk but it still thinks that a fill_summary_index instance is still running:

# ./splunk cmd python fill_summary_index.py 
Please enter the app that contains the search(es): search
An instance of fill_summary_index is already running for app=search

What can I do to cancel it and restart it?

Tags (1)

the_wolverine
Champion

Per Splunk Support, there's a fsidx*.lock file in the app directory that the script was run against. In my case, the search app:

/opt/splunk/etc/apps/search/log]# ls fsidxrlKD2v.lock

After deleting the lock file I was able to relaunch the summary backfill script.

the_wolverine
Champion

Thanks, Alex 😉

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...