Splunk Search

Splunkd service wont start on Windows Server (handler/weak reference error)

jospina2
Explorer

Has anyone encountered this error before? Our splunk instance is completely down.

08-10-2018 12:45:50.153 -0700 INFO loader - win-service: Starting as a Windows service: will run various system checks first...
08-10-2018 12:45:50.169 -0700 INFO loader - win-service: Splunk starting as a local administrator
08-10-2018 12:45:50.169 -0700 INFO loader - Automatic migration of modular inputs
08-10-2018 12:45:52.794 -0700 ERROR loader - win-service: Error running pre-flight-checks (pclose returned 1).
08-10-2018 12:45:52.794 -0700 ERROR loader - win-service: Here is the output from running pre-flight-checks:
08-10-2018 12:45:52.794 -0700 ERROR loader - Checking critical directories... Done
08-10-2018 12:45:52.794 -0700 ERROR loader - Checking indexes...
08-10-2018 12:45:52.794 -0700 ERROR loader - Validated: _audit _internal _introspection _telemetry _thefishbucket add_on_builder_index history iis_logs main perfmon registry summary windows wineventlog
08-10-2018 12:45:52.794 -0700 ERROR loader - Done
08-10-2018 12:45:52.794 -0700 ERROR loader - Traceback (most recent call last):
08-10-2018 12:45:52.794 -0700 ERROR loader - File "C:\Program Files\Splunk\Python-2.7\Lib\site-packages\splunk\clilib\cli.py", line 11, in
08-10-2018 12:45:52.794 -0700 ERROR loader - import logging as logger
08-10-2018 12:45:52.794 -0700 ERROR loader - File "C:\Program Files\Splunk\Python-2.7\Lib\logging__init
_.py", line 618, in
08-10-2018 12:45:52.794 -0700 ERROR loader - _handlers = weakref.WeakValueDictionary() #map of handler names to handlers
08-10-2018 12:45:52.794 -0700 ERROR loader - AttributeError: 'module' object has no attribute 'WeakValueDictionary'
08-10-2018 12:45:52.794 -0700 ERROR loader - <<<<< EOF (pre-flight-checks)

0 Karma

jospina2
Explorer

To resolve this issue I deleted the Entire Python27 folder from Program Files/Splunk

Then I copy & pasted a Python27 folder that has never been modified, and that one worked

so the python files may have been corrupted

SGun
Explorer

Worked fine, thanks

0 Karma
Get Updates on the Splunk Community!

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...