Getting Data In

splunk upgrade from 7.3.3 to 8.0.0 failed (Could not create path D:\splunk\data\index\_metrics\db appearing in indexes.conf: 5 )

jerjer951109
Loves-to-Learn

Hi, anyone know how to solve this problem?

C:\Users\AppData\Local\temp\splunk.log
In the log file is shown :

Could not create path D:\splunk\data\index_metrics\db appearing in indexes.conf: 5
Validating databases (splunk valiadated) failed with code '1'

as we have tried to use Admin account already and can access to this folder D:\splunk\data\index\_metrics.
but we cannot upgrade successfully.

system environment:
Splunk 7.3.3
Windows Server 2012 R2

Tags (3)
0 Karma

woodcock
Esteemed Legend

This is a permissions problem: Splunk cannot create that directory and it MUST in order to run. You can either manually create or give the user that Splunk is running as the permission to create it.

0 Karma

MaverickT
Communicator

Hi,

can you check under which user splunk service is running? By default it is system. This user also needs to have read/write/execute permission on the folder D:\splunk\data\index_metrics\

Just a friendly tip: I suggest you migrate your splunk environment to linux. Since we have done it, our life is much easier.

0 Karma

jerjer951109
Loves-to-Learn

Do you know which user for D:\splunk\data\index\_metrics\?
As currently, we cannot see the owner.

https://imgur.com/ru47Xw8
https://imgur.com/ru47Xw8
https://imgur.com/Wxxa6Rw

0 Karma

jerjer951109
Loves-to-Learn

system user is running splunkd service.
For D:\splunk\data\index\_metrics\, it is read only and it shows that You do not have permission to view this object's security properties, even as an administrator user.

0 Karma

MaverickT
Communicator

@jerjer951109 I see that can be your problem... Try taking over ownership of the folder with your admin account and then you will be able to change the permissions.

0 Karma

jhornsby_splunk
Splunk Employee
Splunk Employee

Hi @jerjer951109 ,

Where are you seeing that message?

Cheers,

- Jo.

0 Karma

jerjer951109
Loves-to-Learn

C:\Users\AppData\Local\temp\splunk.log

0 Karma

jerjer951109
Loves-to-Learn

i upgrade using splunk-8.0.0-x64.msi but failed
then i checked log C:\Users\AppData\Local\temp\splunk.log and see this error

0 Karma

jerjer951109
Loves-to-Learn

OS: Windows server 2012

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...