Splunk Search

is_pid_valid

thiru25
Explorer

I am seeing this error, causing splunk to not start, how can I resolve it?

Operation "is_pid_valid" failed in /opt/splunk/p4/splunk/branches/5.0.2/src/libzero/conf-mutator-locking.c:261, conf_mutator_lock(); Operation not permitted
Conf mutator lockfile has PID 26728, but my PID is 24004; error condition likely.

Tags (2)

andykuhn
Path Finder

In my circumstance, within the /var/run/splunk dir, I had NO .pid file. Otherwise my error and circumstance were identical.

To fix the issue, previous 'session' files were copied to another folder I called 'old_sessions'. Upon restart, with the session data cleared, the pid file regenerated properly and everything looks fine.

0 Karma

gudavasr
Path Finder

In $SPLUNK_HOME/var/run/splunk ..there are files with .pid. One of it is conf-mutator-.pid.
Somehow this file is not deleted when splunk is stopped. Hence this error. To resolve:
1) stop splunk to stop all the process.
2) rename conf-mutator-*.pid
3) start splunk.

Thnak yosu

gudavasr
Path Finder

Hi,

Does any one know solution for this issue? I have the same issue after patching this server.
Can someone please help?

Thank You

0 Karma

droth333
Explorer

Can we get a splunker to comment on this? "Error condition likely",
as in, can you name a few?
This has happened to me too, it can't be that uncommon,
though this issue has low readership.
thanks!

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...