I am executing the following command on a Windows Server 2012 R2 machine with Splunk 6.0.1:
C:\Program Files\Splunk\bin>splunk clean eventdata -index INDEXNAME
This crashes splunk.exe. Windows displays a dialog box with the following information:
Problem signature:
Problem Event Name: APPCRASH
Application Name: splunk.exe
Application Version: 1536.256.0.58811
Application Timestamp: 52ab7b46
Fault Module Name: splunk.exe
Fault Module Version: 1536.256.0.58811
Fault Module Timestamp: 52ab7b46
Exception Code: c0000005
Exception Offset: 00000000000082c0
OS Version: 6.3.9600.2.0.0.272.7
Locale ID: 1031
Additional Information 1: 1cf6
Additional Information 2: 1cf651e9a88f0329c96cc649ff046e69
Additional Information 3: 2fc5
Additional Information 4: 2fc5f68b35a04306c3885ae9727075a7
Splunkd is stopped while I do that, of course.
I'm also seeing the same behavior on Server 2012 (non-R2). This is in an Administrator command window.
I had a server spew some 18 million syslog entries that I'd like to clear out and cannot do so due to this issue.
Same problem here on Win2k8 R2 x64.
yes and yes. still fails with the crash message from the OP above.
I've cleaned indexes on W2K8R2 systems many times. Are you running the command from a cmd window that was started with 'run as administrator', and does the administrator have access to the index directories?