<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk universal forwarder crashing - Crashing thread: parsing in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-crashing-Crashing-thread-parsing/m-p/650152#M110490</link>
    <description>&lt;P&gt;1.&lt;BR /&gt;UF 9.0.4&amp;nbsp;&amp;nbsp;&lt;BR /&gt;OS: Linux&lt;BR /&gt;Arch: x86-64&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;2.&amp;nbsp;&lt;BR /&gt;No upgrade done&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;3.&lt;BR /&gt;No changes. Its a new installation.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;4.&lt;BR /&gt;crashing on only one UF&lt;/P&gt;</description>
    <pubDate>Wed, 12 Jul 2023 11:39:24 GMT</pubDate>
    <dc:creator>Splunker8</dc:creator>
    <dc:date>2023-07-12T11:39:24Z</dc:date>
    <item>
      <title>Splunk universal forwarder crashing - Crashing thread: parsing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-crashing-Crashing-thread-parsing/m-p/650064#M110469</link>
      <description>&lt;P&gt;Splunk universal forwarder crashes&lt;BR /&gt;&lt;BR /&gt;here are crash logs:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;[build de405f4a7979] 2023-07-10 17:31:30&lt;BR /&gt;Received fatal signal 11 (Segmentation fault) on PID 3013854.&lt;BR /&gt;Cause:&lt;BR /&gt;No memory mapped at address [0x0000000000000080].&lt;BR /&gt;Crashing thread: parsing&lt;BR /&gt;Registers:&lt;BR /&gt;RIP: [0x00007FBC41EDEA74] __pthread_mutex_lock + 4 (libpthread.so.0 + 0xAA74)&lt;BR /&gt;RDI: [0x0000000000000070]&lt;BR /&gt;RSI: [0x00007FBC3E21A0B0]&lt;BR /&gt;RBP: [0x00007FBC2FDFD980]&lt;BR /&gt;RSP: [0x00007FBC2FDFD8C8]&lt;BR /&gt;RAX: [0x0000558B2F9877E0]&lt;BR /&gt;RBX: [0x0000000000000000]&lt;BR /&gt;RCX: [0x0000000000000000]&lt;BR /&gt;RDX: [0x00007FBC2FDFD8F8]&lt;BR /&gt;R8: [0x0000000000000000]&lt;BR /&gt;R9: [0x00007FBC41200080]&lt;BR /&gt;R10: [0x00000000000000A3]&lt;BR /&gt;R11: [0x0000000000000000]&lt;BR /&gt;R12: [0x0000000000000001]&lt;BR /&gt;R13: [0x0000000000000070]&lt;BR /&gt;R14: [0x00007FBC2FDFD8F0]&lt;BR /&gt;R15: [0x0000558B2F9877D0]&lt;BR /&gt;EFL: [0x0000000000010202]&lt;BR /&gt;TRAPNO: [0x000000000000000E]&lt;BR /&gt;ERR: [0x0000000000000004]&lt;BR /&gt;CSGSFS: [0x002B000000000033]&lt;BR /&gt;OLDMASK: [0x0000000000000000]&lt;/P&gt;&lt;P&gt;OS: Linux&lt;BR /&gt;Arch: x86-64&lt;/P&gt;&lt;P&gt;Backtrace (PIC build):&lt;BR /&gt;[0x00007FBC41EDEA74] __pthread_mutex_lock + 4 (libpthread.so.0 + 0xAA74)&lt;BR /&gt;[0x0000558B2CE030D9] _ZN16PthreadMutexImpl4lockEv + 9 (splunkd + 0x2DD20D9)&lt;BR /&gt;[0x0000558B2CD3ED27] _ZN9EventLoop20internal_runInThreadEP13InThreadActorb + 103 (splunkd + 0x2D0DD27)&lt;BR /&gt;[0x0000558B2CB7B19A] _ZN11Distributed11EloopRunner3runEPNS_15EloopRunnerTaskE + 170 (splunkd + 0x2B4A19A)&lt;BR /&gt;[0x0000558B2C02A6A6] _ZN18TcpOutputProcessor7executeER15CowPipelineData + 230 (splunkd + 0x1FF96A6)&lt;BR /&gt;[0x0000558B2C7B1B29] _ZN9Processor12executeMultiER18PipelineDataVectorPS0_ + 73 (splunkd + 0x2780B29)&lt;BR /&gt;[0x0000558B2BDA03A2] _ZN8Pipeline4mainEv + 1074 (splunkd + 0x1D6F3A2)&lt;BR /&gt;[0x0000558B2CE02DAD] _ZN6Thread37_callMainAndDiscardTerminateExceptionEv + 13 (splunkd + 0x2DD1DAD)&lt;BR /&gt;[0x0000558B2CE03CA2] _ZN6Thread8callMainEPv + 178 (splunkd + 0x2DD2CA2)&lt;BR /&gt;[0x00007FBC41EDC1CF] ? (libpthread.so.0 + 0x81CF)&lt;BR /&gt;[0x00007FBC4146ADD3] clone + 67 (libc.so.6 + 0x39DD3)&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2023 22:38:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-crashing-Crashing-thread-parsing/m-p/650064#M110469</guid>
      <dc:creator>Splunker8</dc:creator>
      <dc:date>2023-07-11T22:38:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk universal forwarder crashing - Crashing thread: parsing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-crashing-Crashing-thread-parsing/m-p/650070#M110471</link>
      <description>&lt;P&gt;Submit a support request.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2023 00:39:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-crashing-Crashing-thread-parsing/m-p/650070#M110471</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-07-12T00:39:33Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk universal forwarder crashing - Crashing thread: parsing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-crashing-Crashing-thread-parsing/m-p/650075#M110474</link>
      <description>&lt;P&gt;Splunk UF crashing logs analysis is a difficult task.. only Splunk Support guys can do that. if you have the support contract, pls make a support ticket..&lt;/P&gt;&lt;P&gt;also just for learning purposes...&lt;/P&gt;&lt;P&gt;1) the UF version, linux or win, pls&lt;/P&gt;&lt;P&gt;2) did you do any UF upgrade recently?&amp;nbsp;&lt;/P&gt;&lt;P&gt;3) any new config files, did you push from DS to this UF?&lt;/P&gt;&lt;P&gt;4) do you face this UF crash issue only one UF or multiple UFs&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2023 01:27:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-crashing-Crashing-thread-parsing/m-p/650075#M110474</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2023-07-12T01:27:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk universal forwarder crashing - Crashing thread: parsing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-crashing-Crashing-thread-parsing/m-p/650152#M110490</link>
      <description>&lt;P&gt;1.&lt;BR /&gt;UF 9.0.4&amp;nbsp;&amp;nbsp;&lt;BR /&gt;OS: Linux&lt;BR /&gt;Arch: x86-64&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;2.&amp;nbsp;&lt;BR /&gt;No upgrade done&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;3.&lt;BR /&gt;No changes. Its a new installation.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;4.&lt;BR /&gt;crashing on only one UF&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2023 11:39:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-crashing-Crashing-thread-parsing/m-p/650152#M110490</guid>
      <dc:creator>Splunker8</dc:creator>
      <dc:date>2023-07-12T11:39:24Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk universal forwarder crashing - Crashing thread: parsing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-crashing-Crashing-thread-parsing/m-p/650300#M110507</link>
      <description>&lt;P&gt;&lt;EM&gt;4.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;crashing on only one UF&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;.... if you are looking for short answer... uninstall that 9.0.4 UF, use another UF version... either 9.0.0 or 9.1.0..etc..&lt;/P&gt;&lt;P&gt;if you are looking for a perfect solution, then, Splunk support ticket is the only answer. (9.0.4 UF is a recent one... the linux and that UF may have some compatibility issues or.. that particular linux is giving some troubles to the UF.. only Splunk Support guys can solve this issues.. thanks.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2023 00:16:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-crashing-Crashing-thread-parsing/m-p/650300#M110507</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2023-07-13T00:16:11Z</dc:date>
    </item>
  </channel>
</rss>

