I ran the upgrade to 5.0 of the Palo app and now Splunk won't start. When I try to start the service I get the below error.
Checking prerequisites...
Checking http port [8000]: open
Checking mgmt port [8089]: open
Checking appserver port [127.0.0.1:8065]: open
Checking kvstore port [8191]: open
Checking configuration... Done.
Checking critical directories... Done
Checking indexes...
Problem parsing indexes.conf: stanza=flowintegrator Required parameter=homePath not configured
Validating databases (splunkd validatedb) failed with code '1'. If you cannot resolve the issue(s) above after consulting documentation, please file a case online at http://www.splunk.com/page/submit_issue
I looked at the indexes.conf and saw that it was missing the paths to the DB's, so I added them, but it didn't make a difference.
[pan_logs]
maxTotalDataSizeMB = 800000
homePath = /opt/splunk/var/lib/splunk/pan_logs/db
coldPath = /opt/splunk/var/lib/splunk/pan_logs/colddb
thawedPath = /opt/splunk/var/lib/splunk/pan_logs/thaweddb
[flowintegrator]
maxTotalDataSizeMB = 10000
↧