Monitoring Splunk

Splunk Daemon Crashing

cfalzone
New Member

Just downloaded Splunk 4.1.3 for windows 32 bit. Running Windows 7 32 bit Enterprise Edition.

This is what I am getting in my log -- any idea how to fix it? "ERROR WordPositionData - couldn't parse hash code:"

More from the splunkd.log:


06-15-2010 11:44:16.832 INFO  loader - Splunkd starting (build 80534).
06-15-2010 11:44:16.832 INFO  loader - System info: Windows, CFALZONE, 1, 6, Intel.
06-15-2010 11:44:16.832 INFO  loader - Detected 2 (virtual) CPUs and 2814MB RAM
06-15-2010 11:44:16.832 INFO  loader - Getting configuration data from: C:\Program Files\Splunk\etc\myinstall\splunkd.xml
06-15-2010 11:44:16.833 INFO  loader - SPLUNK_MODULE_PATH environment variable not found - defaulting to C:\Program Files\Splunk\etc\modules
06-15-2010 11:44:16.833 INFO  loader - loading modules from C:\Program Files\Splunk\etc\modules
06-15-2010 11:44:16.834 INFO  loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\distributedDeployment
06-15-2010 11:44:16.834 INFO  loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\distributedDeployment\classes
06-15-2010 11:44:16.834 INFO  loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\distributedDeployment\classes\deployable
06-15-2010 11:44:16.834 INFO  loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\distributedDeployment\classes\deploymentserver
06-15-2010 11:44:16.835 INFO  loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\input
06-15-2010 11:44:16.836 INFO  loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\input\TCP
06-15-2010 11:44:16.837 INFO  loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\input\UDP
06-15-2010 11:44:16.837 INFO  loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\input\exec
06-15-2010 11:44:16.838 INFO  loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\input\fschangemanager
06-15-2010 11:44:16.839 INFO  loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\input\log4jTCP
06-15-2010 11:44:16.839 INFO  loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\input\splunkTCP
06-15-2010 11:44:16.839 INFO  loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\input\syslogUDP
06-15-2010 11:44:16.839 INFO  loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\input\tailfile
06-15-2010 11:44:16.841 INFO  loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\input\wineventlog
06-15-2010 11:44:16.842 INFO  loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\internal
06-15-2010 11:44:16.842 INFO  loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\internal\scheduler
06-15-2010 11:44:16.842 INFO  loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\parsing
06-15-2010 11:44:16.844 INFO  loader - Writing out composite configuration file: C:\Program Files\Splunk\var\run\splunk\composite.xml
06-15-2010 11:44:16.892 INFO  LicenseManager - Initializing
06-15-2010 11:44:16.918 INFO  LicenseManager - Looking for bytequotaprocessor...
06-15-2010 11:44:16.918 INFO  LicenseManager - Checking for previous keyed license
06-15-2010 11:44:17.451 INFO  LicenseManager - Using 5 for MAX VIOLATIONS
06-15-2010 11:44:17.451 INFO  LicenseManager - Using 30 for VIOLATION PERIOD (days)
06-15-2010 11:44:17.460 INFO  IndexProcessor - running splunkd specific init
06-15-2010 11:44:17.470 INFO  ServerConfig - My server name is "CFALZONE".
06-15-2010 11:44:17.470 INFO  ServerConfig - Default output queue for file-based input: parsingQueue.
06-15-2010 11:44:17.481 INFO  loader - Initializing from configuration
06-15-2010 11:44:17.483 INFO  PipelineComponent - Pipeline indexerPipe enabled
06-15-2010 11:44:17.483 INFO  loader - Instantiated plugin: queueinputprocessor
06-15-2010 11:44:17.483 INFO  loader - Instantiated plugin: tcpoutputprocessor
06-15-2010 11:44:17.496 INFO  loader - Instantiated plugin: syslogoutputprocessor
06-15-2010 11:44:17.519 INFO  loader - Instantiated plugin: httpoutputprocessor
06-15-2010 11:44:17.542 INFO  loader - Instantiated plugin: indexandforwardprocessor
06-15-2010 11:44:17.565 INFO  loader - Instantiated plugin: bytequotaprocessor
06-15-2010 11:44:17.565 INFO  loader - Instantiated plugin: signingprocessor
06-15-2010 11:44:17.565 INFO  loader - Instantiated plugin: indexprocessor
06-15-2010 11:44:17.565 INFO  IndexProcessor - initializing with fullInit=true
06-15-2010 11:44:17.568 INFO  IndexProcessor - indexes.conf - indexThreads param autotuned to 2
06-15-2010 11:44:17.568 INFO  TPool - initializing IndexerTPool with 2 workers
06-15-2010 11:44:17.568 INFO  IndexProcessor - indexes.conf - memPoolMB param autotuned to 256MB
06-15-2010 11:44:17.568 INFO  MPool - MPool initialized: bytes=268435456 
06-15-2010 11:44:17.569 INFO  HotDBManager - creating hot mgr: C:\Program Files\Splunk\var\lib\splunk\audit\db maxHotSpanSecs=7776000 maxHotBuckets=1 maxDataSizeBytes=786432000 quarantinePastSecs=77760000 quarantineFutureSecs=2592000 
06-15-2010 11:44:17.569 INFO  databasePartitionPolicy - index _audit initialized with [300,60,188697600,,,786432000,20,500000,5,5,false,3,0,_blocksignature,7776000,0,1,77760000,2592000,10485760]
06-15-2010 11:44:17.569 INFO  databasePartitionPolicy - openDatabase for C:\Program Files\Splunk\var\lib\splunk\audit\db
06-15-2010 11:44:17.571 INFO  BucketMover - initiatializing BucketMoverTPool
06-15-2010 11:44:17.571 INFO  TPool - initializing BucketMoverTPool with 5 workers
06-15-2010 11:44:17.572 INFO  databasePartitionPolicy - We are running on a pre-existing database opening ...
06-15-2010 11:44:17.572 INFO  databasePartitionPolicy - Found timestamp file ! at C:\Program Files\Splunk\var\lib\splunk\audit\db\CreationTime
06-15-2010 11:44:17.574 INFO  databasePartitionPolicy - CREATION TIME for C:\Program Files\Splunk\var\lib\splunk\audit\db : 1274814326
06-15-2010 11:44:17.574 INFO  databasePartitionPolicy - opening database C:\Program Files\Splunk\var\lib\splunk\audit\db\hot_v1_0
06-15-2010 11:44:17.574 INFO  timeinvertedIndex - Opening C:\Program Files\Splunk\var\lib\splunk\audit\db\hot_v1_0
06-15-2010 11:44:17.574 INFO  timeinvertedIndex - No files to decompress on create
06-15-2010 11:44:17.574 INFO  timeinvertedIndex - create by dirname C:\Program Files\Splunk\var\lib\splunk\audit\db\hot_v1_0
06-15-2010 11:44:17.576 INFO  databasePartitionPolicy - found hot db with 20813 events
06-15-2010 11:44:17.576 INFO  HotDBManager - recovered hot: hot_v1_0, [id=0, et=1274814325, lt=1275067822]
06-15-2010 11:44:17.581 INFO  databasePartitionPolicy - currentId for C:\Program Files\Splunk\var\lib\splunk\audit\db after openDatabases = 1
06-15-2010 11:44:17.581 INFO  HotDBManager - creating hot mgr: C:\Program Files\Splunk\var\lib\splunk\blockSignature\db maxHotSpanSecs=7776000 maxHotBuckets=1 maxDataSizeBytes=1048576000 quarantinePastSecs=77760000 quarantineFutureSecs=2592000 
06-15-2010 11:44:17.581 INFO  databasePartitionPolicy - index _blocksignature initialized with [300,60,0,,,1048576000,20,0,5,5,false,3,0,_blocksignature,7776000,0,1,77760000,2592000,10485760]
06-15-2010 11:44:17.581 INFO  databasePartitionPolicy - openDatabase for C:\Program Files\Splunk\var\lib\splunk\blockSignature\db
06-15-2010 11:44:17.583 INFO  databasePartitionPolicy - We are running on a pre-existing database opening ...
06-15-2010 11:44:17.583 INFO  databasePartitionPolicy - No databases found starting fresh !
06-15-2010 11:44:17.584 INFO  databasePartitionPolicy - CREATION TIME for C:\Program Files\Splunk\var\lib\splunk\blockSignature\db : 1274814326
06-15-2010 11:44:17.585 INFO  databasePartitionPolicy - currentId for C:\Program Files\Splunk\var\lib\splunk\blockSignature\db after openDatabases = 0
06-15-2010 11:44:17.585 INFO  HotDBManager - creating hot mgr: C:\Program Files\Splunk\var\lib\splunk\_internaldb\db maxHotSpanSecs=7776000 maxHotBuckets=1 maxDataSizeBytes=104857600 quarantinePastSecs=77760000 quarantineFutureSecs=2592000 
06-15-2010 11:44:17.585 INFO  databasePartitionPolicy - index _internal initialized with [300,60,2419200,,,104857600,20,500000,5,5,false,3,0,_blocksignature,7776000,0,1,77760000,2592000,10485760]
06-15-2010 11:44:17.585 INFO  databasePartitionPolicy - openDatabase for C:\Program Files\Splunk\var\lib\splunk\_internaldb\db
06-15-2010 11:44:17.586 ERROR WordPositionData - couldn't parse hash code: 
Tags (1)
0 Karma

macnrg
New Member

can i get infonon my friends computer by having her computer info and serial # and her location?

0 Karma

Lowell
Super Champion

Have you tried contacting splunk support?

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...