Getting Data In

Splunk 6.4.1 migration to new Server

drewsunderland
Explorer

Hello All,

I am having one heck of a time migrating an old server to a new server, both are windows server 2012 r2 with Splunk Enterprise 6.4.1 installed, I have followed the instructions here https://answers.splunk.com/answers/583396/what-is-the-full-process-to-migrate-a-full-splunk-1.html

But when I try this and try to install splunk it fails and rolls back, now if I tell it to not start splunk it installs but I cannot get the splunkd server to start, it keeps giving me an error "Access violation, cannot read at address [0x000000000000020]" in the Splunkd crash log. I am completely out of ideas. The new server is a different IP address and Host name.

Thank you,

0 Karma
1 Solution

drewsunderland
Explorer

I figured out what was causing my issue, there was some frozen buckets configured in an app pointing to a drive that does not exist on the new server, after editing the index file and the server.conf file to change the location of the frozen buckets it was able to install successfully and it has all my data.

Thank you again

View solution in original post

drewsunderland
Explorer

I figured out what was causing my issue, there was some frozen buckets configured in an app pointing to a drive that does not exist on the new server, after editing the index file and the server.conf file to change the location of the frozen buckets it was able to install successfully and it has all my data.

Thank you again

drewsunderland
Explorer

Sorry for the late reply,
We are using a domain account, the password is correct, the service starts and windows shows that it is running but as soon as you refresh the services it is stopped, so when reviewing the splunkd crash log it gets the above error.

0 Karma

xpac
SplunkTrust
SplunkTrust

I don't have a good idea on this - I'd open a support case with Splunk, they might need to do some investigation on this.

0 Karma

xpac
SplunkTrust
SplunkTrust

Just a wild guess: Did you change the user Splunk is running as?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...