Customer reports that Splunk 6.0.0 suddenly stops indexing.
splunkd.log reports errors like
ERROR BTreeCP - error moving save dir 'D:\Splunk\var\lib\splunk\fishbucket\splunk_private_db\save' to old 'D:\Splunk\var\lib\splunk\fishbucket\splunk_private_db\save.old' while truncating
ERROR BTreeCP - addUpdate: IOException caught: BTree::Exception: error moving save dir 'D:\Splunk\var\lib\splunk\fishbucket\splunk_private_db\save' to old 'D:\Splunk\var\lib\splunk\fishbucket\splunk_private_db\save.old' while truncating.
Splunk SOS app shows Indexing, Typing , Aggregation & Parsing Queues are blocked.
Splunk are currently investing an issue when _fishbucket reaches maxDataSize. (SPL-82042)
A workaround is to:
1. splunk stop
2. Check the size of maxDataSize in stanza [_thefishbucket]
3. Create $SPLUNK_HOME/etc/system/local/indexes.conf with an increased maxDataSize value eg
[_thefishbucket]
maxDataSize = 1500
4. Restart Splunk
A permanent fix will be included in a future maintenance release of Splunk.