Knowledge Management

Why do the indexes disappear in Settings>Indexes after upgrade to v7.0.2 from v6.6.2?

johnmai
New Member

Currently being hosted on Win2012 R2.

Splunk is installed on C:\ and E:\, with splunk-launch.conf pointing to E:..

However once I complete the upgrade, the indexes disappear from the Webpage Splunk > Settings > Indexes but the search is still working.
I can create a new index which ends up in E:\ but after creation it doesn't appear within Settings > Indexes.

Error:
Installed Files Integrity Checker: Unable to access or parse the contents of manifest file in SPLUNK_HOME directory. As a result, file integrity information is not available. Verify manifest file in SPLUNK_HOME directory is still present, and that the splunk service user context will have read-access.

Confirmed using same account which originally installed Splunk v6.6.2

0 Karma

valiquet
Contributor

Are you on a distributed env?

0 Karma

p_gurav
Champion

Can you check the value of $SPLUNK_HOME?

0 Karma

johnmai
New Member

It's pointing to E:\Splunk\index

And the indexes are E:\Splunk\index\var\lib\splunk

0 Karma

adonio
Ultra Champion

can you elaborate?
what does it mean splunk installed on C:\ and E:\?
where are the splunk binaries?
can you share your full splunk-launch.conf including:

SPLUNK_HOME
SPLUNK_DB

when you are running the command | dbinspect or | rest /services/data/indexes | table title homePath_expanded coldPath_expanded
what are the results?

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...