Just downloaded Splunk 4.1.3 for windows 32 bit. Running Windows 7 32 bit Enterprise Edition.
This is what I am getting in my log -- any idea how to fix it?
"ERROR WordPositionData - couldn't parse hash code:"
More from the splunkd.log:
06-15-2010 11:44:16.832 INFO loader - Splunkd starting (build 80534).
06-15-2010 11:44:16.832 INFO loader - System info: Windows, CFALZONE, 1, 6, Intel.
06-15-2010 11:44:16.832 INFO loader - Detected 2 (virtual) CPUs and 2814MB RAM
06-15-2010 11:44:16.832 INFO loader - Getting configuration data from: C:\Program Files\Splunk\etc\myinstall\splunkd.xml
06-15-2010 11:44:16.833 INFO loader - SPLUNK_MODULE_PATH environment variable not found - defaulting to C:\Program Files\Splunk\etc\modules
06-15-2010 11:44:16.833 INFO loader - loading modules from C:\Program Files\Splunk\etc\modules
06-15-2010 11:44:16.834 INFO loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\distributedDeployment
06-15-2010 11:44:16.834 INFO loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\distributedDeployment\classes
06-15-2010 11:44:16.834 INFO loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\distributedDeployment\classes\deployable
06-15-2010 11:44:16.834 INFO loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\distributedDeployment\classes\deploymentserver
06-15-2010 11:44:16.835 INFO loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\input
06-15-2010 11:44:16.836 INFO loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\input\TCP
06-15-2010 11:44:16.837 INFO loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\input\UDP
06-15-2010 11:44:16.837 INFO loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\input\exec
06-15-2010 11:44:16.838 INFO loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\input\fschangemanager
06-15-2010 11:44:16.839 INFO loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\input\log4jTCP
06-15-2010 11:44:16.839 INFO loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\input\splunkTCP
06-15-2010 11:44:16.839 INFO loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\input\syslogUDP
06-15-2010 11:44:16.839 INFO loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\input\tailfile
06-15-2010 11:44:16.841 INFO loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\input\wineventlog
06-15-2010 11:44:16.842 INFO loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\internal
06-15-2010 11:44:16.842 INFO loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\internal\scheduler
06-15-2010 11:44:16.842 INFO loader - Processing Module ----> C:\Program Files\Splunk\etc\modules\parsing
06-15-2010 11:44:16.844 INFO loader - Writing out composite configuration file: C:\Program Files\Splunk\var\run\splunk\composite.xml
06-15-2010 11:44:16.892 INFO LicenseManager - Initializing
06-15-2010 11:44:16.918 INFO LicenseManager - Looking for bytequotaprocessor...
06-15-2010 11:44:16.918 INFO LicenseManager - Checking for previous keyed license
06-15-2010 11:44:17.451 INFO LicenseManager - Using 5 for MAX VIOLATIONS
06-15-2010 11:44:17.451 INFO LicenseManager - Using 30 for VIOLATION PERIOD (days)
06-15-2010 11:44:17.460 INFO IndexProcessor - running splunkd specific init
06-15-2010 11:44:17.470 INFO ServerConfig - My server name is "CFALZONE".
06-15-2010 11:44:17.470 INFO ServerConfig - Default output queue for file-based input: parsingQueue.
06-15-2010 11:44:17.481 INFO loader - Initializing from configuration
06-15-2010 11:44:17.483 INFO PipelineComponent - Pipeline indexerPipe enabled
06-15-2010 11:44:17.483 INFO loader - Instantiated plugin: queueinputprocessor
06-15-2010 11:44:17.483 INFO loader - Instantiated plugin: tcpoutputprocessor
06-15-2010 11:44:17.496 INFO loader - Instantiated plugin: syslogoutputprocessor
06-15-2010 11:44:17.519 INFO loader - Instantiated plugin: httpoutputprocessor
06-15-2010 11:44:17.542 INFO loader - Instantiated plugin: indexandforwardprocessor
06-15-2010 11:44:17.565 INFO loader - Instantiated plugin: bytequotaprocessor
06-15-2010 11:44:17.565 INFO loader - Instantiated plugin: signingprocessor
06-15-2010 11:44:17.565 INFO loader - Instantiated plugin: indexprocessor
06-15-2010 11:44:17.565 INFO IndexProcessor - initializing with fullInit=true
06-15-2010 11:44:17.568 INFO IndexProcessor - indexes.conf - indexThreads param autotuned to 2
06-15-2010 11:44:17.568 INFO TPool - initializing IndexerTPool with 2 workers
06-15-2010 11:44:17.568 INFO IndexProcessor - indexes.conf - memPoolMB param autotuned to 256MB
06-15-2010 11:44:17.568 INFO MPool - MPool initialized: bytes=268435456
06-15-2010 11:44:17.569 INFO HotDBManager - creating hot mgr: C:\Program Files\Splunk\var\lib\splunk\audit\db maxHotSpanSecs=7776000 maxHotBuckets=1 maxDataSizeBytes=786432000 quarantinePastSecs=77760000 quarantineFutureSecs=2592000
06-15-2010 11:44:17.569 INFO databasePartitionPolicy - index _audit initialized with [300,60,188697600,,,786432000,20,500000,5,5,false,3,0,_blocksignature,7776000,0,1,77760000,2592000,10485760]
06-15-2010 11:44:17.569 INFO databasePartitionPolicy - openDatabase for C:\Program Files\Splunk\var\lib\splunk\audit\db
06-15-2010 11:44:17.571 INFO BucketMover - initiatializing BucketMoverTPool
06-15-2010 11:44:17.571 INFO TPool - initializing BucketMoverTPool with 5 workers
06-15-2010 11:44:17.572 INFO databasePartitionPolicy - We are running on a pre-existing database opening ...
06-15-2010 11:44:17.572 INFO databasePartitionPolicy - Found timestamp file ! at C:\Program Files\Splunk\var\lib\splunk\audit\db\CreationTime
06-15-2010 11:44:17.574 INFO databasePartitionPolicy - CREATION TIME for C:\Program Files\Splunk\var\lib\splunk\audit\db : 1274814326
06-15-2010 11:44:17.574 INFO databasePartitionPolicy - opening database C:\Program Files\Splunk\var\lib\splunk\audit\db\hot_v1_0
06-15-2010 11:44:17.574 INFO timeinvertedIndex - Opening C:\Program Files\Splunk\var\lib\splunk\audit\db\hot_v1_0
06-15-2010 11:44:17.574 INFO timeinvertedIndex - No files to decompress on create
06-15-2010 11:44:17.574 INFO timeinvertedIndex - create by dirname C:\Program Files\Splunk\var\lib\splunk\audit\db\hot_v1_0
06-15-2010 11:44:17.576 INFO databasePartitionPolicy - found hot db with 20813 events
06-15-2010 11:44:17.576 INFO HotDBManager - recovered hot: hot_v1_0, [id=0, et=1274814325, lt=1275067822]
06-15-2010 11:44:17.581 INFO databasePartitionPolicy - currentId for C:\Program Files\Splunk\var\lib\splunk\audit\db after openDatabases = 1
06-15-2010 11:44:17.581 INFO HotDBManager - creating hot mgr: C:\Program Files\Splunk\var\lib\splunk\blockSignature\db maxHotSpanSecs=7776000 maxHotBuckets=1 maxDataSizeBytes=1048576000 quarantinePastSecs=77760000 quarantineFutureSecs=2592000
06-15-2010 11:44:17.581 INFO databasePartitionPolicy - index _blocksignature initialized with [300,60,0,,,1048576000,20,0,5,5,false,3,0,_blocksignature,7776000,0,1,77760000,2592000,10485760]
06-15-2010 11:44:17.581 INFO databasePartitionPolicy - openDatabase for C:\Program Files\Splunk\var\lib\splunk\blockSignature\db
06-15-2010 11:44:17.583 INFO databasePartitionPolicy - We are running on a pre-existing database opening ...
06-15-2010 11:44:17.583 INFO databasePartitionPolicy - No databases found starting fresh !
06-15-2010 11:44:17.584 INFO databasePartitionPolicy - CREATION TIME for C:\Program Files\Splunk\var\lib\splunk\blockSignature\db : 1274814326
06-15-2010 11:44:17.585 INFO databasePartitionPolicy - currentId for C:\Program Files\Splunk\var\lib\splunk\blockSignature\db after openDatabases = 0
06-15-2010 11:44:17.585 INFO HotDBManager - creating hot mgr: C:\Program Files\Splunk\var\lib\splunk\_internaldb\db maxHotSpanSecs=7776000 maxHotBuckets=1 maxDataSizeBytes=104857600 quarantinePastSecs=77760000 quarantineFutureSecs=2592000
06-15-2010 11:44:17.585 INFO databasePartitionPolicy - index _internal initialized with [300,60,2419200,,,104857600,20,500000,5,5,false,3,0,_blocksignature,7776000,0,1,77760000,2592000,10485760]
06-15-2010 11:44:17.585 INFO databasePartitionPolicy - openDatabase for C:\Program Files\Splunk\var\lib\splunk\_internaldb\db
06-15-2010 11:44:17.586 ERROR WordPositionData - couldn't parse hash code:
... View more