Splunk Search

Why is Splunk Service not starting with 'authDb' error?

New Member

Hi - any idea why my Splunk service is failing with this error?

What is 'authDb'?

~]# service splunk start
Starting Splunk...

Splunk> CSI: Logfiles.

Checking prerequisites...
Checking http port [8000]: open
Checking mgmt port [8089]: open
Checking appserver port []: open
Checking kvstore port [8191]: open
Checking configuration... Done.
Creating: /mnt/splunk_hot//authDb
Warning: cannot create "/mnt/splunk_hot//authDb"

Tags (1)
0 Karma


It would seem Splunk does not have permissions to write. Confirm the user Splunk runs as has ownership of the installation and that there are no storage issues.

chown -R splunk:splunk /mnt/*

Get Updates on the Splunk Community!

Splunk Lantern | Spotlight on Security: Adoption Motions, War Stories, and More

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Cloud | Empowering Splunk Administrators with Admin Config Service (ACS)

Greetings, Splunk Cloud Admins and Splunk enthusiasts! The Admin Configuration Service (ACS) team is excited ...

Tech Talk | One Log to Rule Them All

One log to rule them all: how you can centralize your troubleshooting with Splunk logs We know how important ...