Deployment Architecture

What does an error opening a metaManifest file signify?

hulahoop
Splunk Employee
Splunk Employee

We are seeing these messages in splunkd.log:

07-29-2010 14:26:34.729 ERROR databasePartitionPolicy - unable to open file: /u01/app/splunk/var/lib/splunk/historydb/db/.metaManifest (No such file or directory)

What does it mean? Does it need to be addressed? If so, what to do?

Tags (1)
1 Solution

jbsplunk
Splunk Employee
Splunk Employee

This is a problem with 4.1.5. As long as the file exists, and you aren't experiencing any other issues symptoms, the message can be ignored. It will be resolved with 4.1.6.

View solution in original post

jbsplunk
Splunk Employee
Splunk Employee

This is a problem with 4.1.5. As long as the file exists, and you aren't experiencing any other issues symptoms, the message can be ignored. It will be resolved with 4.1.6.

rjyetter
Path Finder

# 7/29/10 3:22:01.171 PM

07-29-2010 15:22:01.171 ERROR databasePartitionPolicy - unable to open file: /u01/app/splunk/var/lib/splunk/os/db/.metaManifest (No such file or directory)

* host=plaxslcs001.apollogrp.edu   Options|  
* sourcetype=splunkd   Options|  
* source=/u01/app/splunk/var/log/splunk/splunkd.log   Options

# 2 7/29/10 2:26:34.805 PM

07-29-2010 14:26:34.805 ERROR databasePartitionPolicy - unable to open file: /u01/app/splunk/var/lib/splunk/summarydb/db/.metaManifest (No such file or directory)

* host=plaxslcs001.apollogrp.edu   Options|  
* sourcetype=splunkd   Options|  
* source=/u01/app/splunk/var/log/splunk/splunkd.log   Options

# 3 7/29/10 2:26:34.780 PM

07-29-2010 14:26:34.780 ERROR databasePartitionPolicy - unable to open file: /u01/app/splunk/var/lib/splunk/sample/db/.metaManifest (No such file or directory)

* host=plaxslcs001.apollogrp.edu   Options|  
* sourcetype=splunkd   Options|  
* source=/u01/app/splunk/var/log/splunk/splunkd.log   Options

# 4 7/29/10 2:26:34.753 PM

07-29-2010 14:26:34.753 ERROR databasePartitionPolicy - unable to open file: /u01/app/splunk/var/lib/splunk/defaultdb/db/.metaManifest (No such file or directory)

* host=plaxslcs001.apollogrp.edu   Options|  
* sourcetype=splunkd   Options|  
* source=/u01/app/splunk/var/log/splunk/splunkd.log   Options

# 5 7/29/10 2:26:34.729 PM

07-29-2010 14:26:34.729 ERROR databasePartitionPolicy - unable to open file: /u01/app/splunk/var/lib/splunk/historydb/db/.metaManifest (No such file or directory)

* host=plaxslcs001.apollogrp.edu   Options|  
* sourcetype=splunkd   Options|  
* source=/u01/app/splunk/var/log/splunk/splunkd.log   Options

# 6 7/29/10 2:26:34.704 PM

07-29-2010 14:26:34.704 ERROR databasePartitionPolicy - unable to open file: /u01/app/splunk/var/lib/splunk/fishbucket/db/.metaManifest (No such file or directory)

* host=plaxslcs001.apollogrp.edu   Options|  
* sourcetype=splunkd   Options|  
* source=/u01/app/splunk/var/log/splunk/splunkd.log   Options

# 7 7/29/10 2:26:34.679 PM

07-29-2010 14:26:34.679 ERROR databasePartitionPolicy - unable to open file: /u01/app/splunk/var/lib/splunk/_internaldb/db/.metaManifest (No such file or directory)

* host=plaxslcs001.apollogrp.edu   Options|  
* sourcetype=splunkd   Options|  
* source=/u01/app/splunk/var/log/splunk/splunkd.log   Options

# 8 7/29/10 2:26:34.654 PM

07-29-2010 14:26:34.654 ERROR databasePartitionPolicy - unable to open file: /u01/app/splunk/var/lib/splunk/blockSignature/db/.metaManifest (No such file or directory)

* host=plaxslcs001.apollogrp.edu   Options|  
* sourcetype=splunkd   Options|  
* source=/u01/app/splunk/var/log/splunk/splunkd.log   Options

# 9 7/29/10 2:26:34.629 PM

07-29-2010 14:26:34.629 ERROR databasePartitionPolicy - unable to open file: /u01/app/splunk/var/lib/splunk/audit/db/.metaManifest (No such file or directory)

* host=plaxslcs001.apollogrp.edu   Options|  
* sourcetype=splunkd   Options|  
* source=/u01/app/splunk/var/log/splunk/splunkd.log   Options
0 Karma

rjyetter
Path Finder

This is happening during normal operations.. What we are doing is importing a TON of data in to Splunk. So far we are indexing about 5 billion events and for some reason the index is choking now. I can see where it processed files from a specific date and yet it shows no data when looking at that date or date range. I think the two are correlated.

0 Karma

Lowell
Super Champion

If you can't get data from your index, then I would suggest noting that in the title of your question. You may get a faster response.

0 Karma

Lowell
Super Champion

Also, do you see this for any indexes other that "historydb" (which I don't think is used anymore)

0 Karma

Lowell
Super Champion

Did this happen when starting up splunkd, or just in the middle of normal operations?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...