Splunk Search

is_pid_valid

thiru25
Explorer

I am seeing this error, causing splunk to not start, how can I resolve it?

Operation "is_pid_valid" failed in /opt/splunk/p4/splunk/branches/5.0.2/src/libzero/conf-mutator-locking.c:261, conf_mutator_lock(); Operation not permitted
Conf mutator lockfile has PID 26728, but my PID is 24004; error condition likely.

Tags (2)

andykuhn
Path Finder

In my circumstance, within the /var/run/splunk dir, I had NO .pid file. Otherwise my error and circumstance were identical.

To fix the issue, previous 'session' files were copied to another folder I called 'old_sessions'. Upon restart, with the session data cleared, the pid file regenerated properly and everything looks fine.

0 Karma

gudavasr
Path Finder

In $SPLUNK_HOME/var/run/splunk ..there are files with .pid. One of it is conf-mutator-.pid.
Somehow this file is not deleted when splunk is stopped. Hence this error. To resolve:
1) stop splunk to stop all the process.
2) rename conf-mutator-*.pid
3) start splunk.

Thnak yosu

gudavasr
Path Finder

Hi,

Does any one know solution for this issue? I have the same issue after patching this server.
Can someone please help?

Thank You

0 Karma

droth333
Explorer

Can we get a splunker to comment on this? "Error condition likely",
as in, can you name a few?
This has happened to me too, it can't be that uncommon,
though this issue has low readership.
thanks!

0 Karma
Get Updates on the Splunk Community!

New This Month in Splunk Observability Cloud - Metrics Usage Analytics, Enhanced K8s ...

The latest enhancements across the Splunk Observability portfolio deliver greater flexibility, better data and ...

Alerting Best Practices: How to Create Good Detectors

At their best, detectors and the alerts they trigger notify teams when applications aren’t performing as ...

Discover Powerful New Features in Splunk Cloud Platform: Enhanced Analytics, ...

Hey Splunky people! We are excited to share the latest updates in Splunk Cloud Platform 9.3.2408. In this ...