Getting Data In

splunk upgrade from 7.3.3 to 8.0.0 failed (Could not create path D:\splunk\data\index\_metrics\db appearing in indexes.conf: 5 )

jerjer951109
Loves-to-Learn

Hi, anyone know how to solve this problem?

C:\Users\AppData\Local\temp\splunk.log
In the log file is shown :

Could not create path D:\splunk\data\index_metrics\db appearing in indexes.conf: 5
Validating databases (splunk valiadated) failed with code '1'

as we have tried to use Admin account already and can access to this folder D:\splunk\data\index\_metrics.
but we cannot upgrade successfully.

system environment:
Splunk 7.3.3
Windows Server 2012 R2

Tags (3)
0 Karma

woodcock
Esteemed Legend

This is a permissions problem: Splunk cannot create that directory and it MUST in order to run. You can either manually create or give the user that Splunk is running as the permission to create it.

0 Karma

MaverickT
Communicator

Hi,

can you check under which user splunk service is running? By default it is system. This user also needs to have read/write/execute permission on the folder D:\splunk\data\index_metrics\

Just a friendly tip: I suggest you migrate your splunk environment to linux. Since we have done it, our life is much easier.

0 Karma

jerjer951109
Loves-to-Learn

Do you know which user for D:\splunk\data\index\_metrics\?
As currently, we cannot see the owner.

https://imgur.com/ru47Xw8
https://imgur.com/ru47Xw8
https://imgur.com/Wxxa6Rw

0 Karma

jerjer951109
Loves-to-Learn

system user is running splunkd service.
For D:\splunk\data\index\_metrics\, it is read only and it shows that You do not have permission to view this object's security properties, even as an administrator user.

0 Karma

MaverickT
Communicator

@jerjer951109 I see that can be your problem... Try taking over ownership of the folder with your admin account and then you will be able to change the permissions.

0 Karma

jhornsby_splunk
Splunk Employee
Splunk Employee

Hi @jerjer951109 ,

Where are you seeing that message?

Cheers,

- Jo.

0 Karma

jerjer951109
Loves-to-Learn

C:\Users\AppData\Local\temp\splunk.log

0 Karma

jerjer951109
Loves-to-Learn

i upgrade using splunk-8.0.0-x64.msi but failed
then i checked log C:\Users\AppData\Local\temp\splunk.log and see this error

0 Karma

jerjer951109
Loves-to-Learn

OS: Windows server 2012

0 Karma
Get Updates on the Splunk Community!

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...