Security

having hundreds of sqlitePersistentStorageImp errors in splunkd logs

univofmem
Engager

04-01-2016 06:55:15.159 -0500 ERROR SQLitePersistentStorageImpl - Error processing enumerate: database disk image is malformed
04-01-2016 06:55:16.538 -0500 ERROR FSChangeMonitor - Exception thrown in update(2) - continuing

This happened after server crashed due to raid card error

Tags (1)
0 Karma
1 Solution

rmorlen_splunk
Splunk Employee
Splunk Employee

To correct this, browse to /opt/splunk/var/lib/splunk/persistentstorage/fschangemanager_state/ and in that directory, there is also a file called "fschangemanager_state". Rename that file or move it to a temporary location and then restart Splunk.

View solution in original post

rmorlen_splunk
Splunk Employee
Splunk Employee

To correct this, browse to /opt/splunk/var/lib/splunk/persistentstorage/fschangemanager_state/ and in that directory, there is also a file called "fschangemanager_state". Rename that file or move it to a temporary location and then restart Splunk.

univofmem
Engager

Thanks..Fixed it.

0 Karma

brent_weaver
Builder

I am seeing this error on a system with a UF, does this process need to be done on the UF or the splunk server. If splunk server, which server in a distributed env?

0 Karma

rmorlen_splunk
Splunk Employee
Splunk Employee

This would be on the server running the UF since it is doing the monitoring.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...