Splunk Search

Unable to stat the splunk indexer missing: /app/splunk/openssl directory

Mayanakhan
Explorer

Hi,

We are unable to start the our one of the indexer in cluster getting the below error. Can we copy the directory "/app/splunk/openssl" from any other indexer in cluster and start? is that fine or we need to follow ant other approach?

Cannot start; missing essential directory: /app/splunk/openssl
        Checking critical directories...Validating databases (splunkd validatedb) failed with code '11'.  If you cannot resolve the issue(s) above after consulting documentation, please file a case online at http://www.splunk.com/page/submit_issue
0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi,

Yes, you can copy it from other Splunk Enterprise Instance but make sure that you copy it from same version of Splunk Enterprise instance.

After copying directory make sure that permissions are also correct.

View solution in original post

harsmarvania57
Ultra Champion

Hi,

Yes, you can copy it from other Splunk Enterprise Instance but make sure that you copy it from same version of Splunk Enterprise instance.

After copying directory make sure that permissions are also correct.

Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...