<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Search Head getting crashed in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Search-Head-getting-crashed/m-p/392086#M7578</link>
    <description>&lt;P&gt;See if this helps:&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/330827/after-upgrade-from-62-to-63-unable-to-start-splunk.html"&gt;https://answers.splunk.com/answers/330827/after-upgrade-from-62-to-63-unable-to-start-splunk.html&lt;/A&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;vranjith009 · Dec 07, 2015 at 10:25 PM
Thanks mfrost8 for your reply.

Error was due to some permission issue of audit db files and "indexes.conf" . Given splunk:splunk permission to all audit db buckets and tracing of bad index conf file by using "./splunk cmd btool indexes list --debug|more" help us for closing the issue.
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Fri, 03 Aug 2018 11:33:03 GMT</pubDate>
    <dc:creator>jkat54</dc:creator>
    <dc:date>2018-08-03T11:33:03Z</dc:date>
    <item>
      <title>Search Head getting crashed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Search-Head-getting-crashed/m-p/392084#M7576</link>
      <description>&lt;P&gt;Our Primary search head got crashed twice today. When cross verified we found out this is the error message in Crash.log so how should we need to fix it asap.&lt;/P&gt;

&lt;P&gt;Error Message:&lt;BR /&gt;
Received fatal signal 6 (Aborted).&lt;BR /&gt;
 Cause:&lt;BR /&gt;
   Signal sent by PID xxx36 running under UID 99xx.&lt;BR /&gt;
 Crashing thread: IdataDO_Collector&lt;/P&gt;</description>
      <pubDate>Fri, 03 Aug 2018 10:59:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Search-Head-getting-crashed/m-p/392084#M7576</guid>
      <dc:creator>anandhalagarasa</dc:creator>
      <dc:date>2018-08-03T10:59:27Z</dc:date>
    </item>
    <item>
      <title>Re: Search Head getting crashed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Search-Head-getting-crashed/m-p/392085#M7577</link>
      <description>&lt;P&gt;Hey@anandhalagarasan,&lt;/P&gt;

&lt;P&gt;What version of splunk are you using?&lt;/P&gt;</description>
      <pubDate>Fri, 03 Aug 2018 11:27:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Search-Head-getting-crashed/m-p/392085#M7577</guid>
      <dc:creator>deepashri_123</dc:creator>
      <dc:date>2018-08-03T11:27:42Z</dc:date>
    </item>
    <item>
      <title>Re: Search Head getting crashed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Search-Head-getting-crashed/m-p/392086#M7578</link>
      <description>&lt;P&gt;See if this helps:&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/330827/after-upgrade-from-62-to-63-unable-to-start-splunk.html"&gt;https://answers.splunk.com/answers/330827/after-upgrade-from-62-to-63-unable-to-start-splunk.html&lt;/A&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;vranjith009 · Dec 07, 2015 at 10:25 PM
Thanks mfrost8 for your reply.

Error was due to some permission issue of audit db files and "indexes.conf" . Given splunk:splunk permission to all audit db buckets and tracing of bad index conf file by using "./splunk cmd btool indexes list --debug|more" help us for closing the issue.
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 03 Aug 2018 11:33:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Search-Head-getting-crashed/m-p/392086#M7578</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2018-08-03T11:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: Search Head getting crashed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Search-Head-getting-crashed/m-p/392087#M7579</link>
      <description>&lt;P&gt;Splunk 6.5.0 (build 59c8927def0f)&lt;/P&gt;</description>
      <pubDate>Fri, 03 Aug 2018 13:08:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Search-Head-getting-crashed/m-p/392087#M7579</guid>
      <dc:creator>anandhalagarasa</dc:creator>
      <dc:date>2018-08-03T13:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: Search Head getting crashed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Search-Head-getting-crashed/m-p/392088#M7580</link>
      <description>&lt;P&gt;Hi there, &lt;BR /&gt;
Just making sure, did you check the following conditions, &lt;/P&gt;

&lt;P&gt;Having enough disk space - For linux,&lt;CODE&gt;du -sh $SPLUNK_HOME/&lt;/CODE&gt;&lt;BR /&gt;
Any user running expensive searches - If you've configured Monitoring console, you can navigate to &lt;CODE&gt;search -&amp;gt; Activity -&amp;gt; Search Activity: Instance&lt;/CODE&gt; OR go to &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.1.2/Search/ViewsearchjobpropertieswiththeJobInspector"&gt;Jobs Manager&lt;/A&gt; page. &lt;/P&gt;</description>
      <pubDate>Fri, 03 Aug 2018 14:32:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Search-Head-getting-crashed/m-p/392088#M7580</guid>
      <dc:creator>sudosplunk</dc:creator>
      <dc:date>2018-08-03T14:32:06Z</dc:date>
    </item>
  </channel>
</rss>

