<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunkd Crash Every Ten Minutes in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Splunkd-Crash-Every-Ten-Minutes/m-p/531892#M6968</link>
    <description>&lt;P&gt;May have Identified the source of the crash as SplunkAppForWebAnalytics Acceleration Job that 'fires' every ten minutes crashing the "BucketSummaryActorThread" but now need to figure out how to address it.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;ERROR SavedSplunker - savedsearch_id="nobody;SplunkAppForWebAnalytics;_ACCELERATE_DM_SplunkAppForWebAnalytics_Web_ACCELERATE_", message="The search job&lt;/P&gt;</description>
    <pubDate>Thu, 03 Dec 2020 16:59:10 GMT</pubDate>
    <dc:creator>gearmstrong</dc:creator>
    <dc:date>2020-12-03T16:59:10Z</dc:date>
    <item>
      <title>Splunkd Crash Every Ten Minutes</title>
      <link>https://community.splunk.com/t5/Installation/Splunkd-Crash-Every-Ten-Minutes/m-p/531887#M6966</link>
      <description>&lt;P&gt;Good day,&lt;BR /&gt;&lt;BR /&gt;Just installed Splunk Enterprise 8.1.0.1 onto New (all-in-one) (moved drive from old system to new) Windows DataCenter Server 2019 Core over top of 8.0.0.&amp;nbsp; Initially got some Splunkd Crashes related to incompatible Python2 code in Apps that prevented splund from starting.&amp;nbsp; Disabled offending apps from command-line and... all good.&amp;nbsp; &amp;nbsp;New System is 56GB memory, 16 vCPUs.&amp;nbsp; I have two indexes (colddb paths) set to F: and G: while Warm/Hot indexes still exist on E: drives.&lt;/P&gt;&lt;P&gt;Today I noticed that splunkd is still crashing but on a different thread from the one that halted splunkd.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Access violation, cannot read at address [0x000002EC99CBE6F8] Exception address:&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; [0x00007FF65CF8EAB6] Crashing thread: BucketSummaryActorThread&lt;/P&gt;&lt;P data-unlink="true"&gt;The only 'direct' reference I found to this was for&amp;nbsp;Transparent huge memory pages (THP)&amp;nbsp;&amp;nbsp;being disabled on a Linux System but nothing relevant to a Windows 2019 Core system.&amp;nbsp; I'm sure there are some parallels here between memory management on Linux and Core but I don't see them.&lt;/P&gt;&lt;P data-unlink="true"&gt;Any assistance is appreciated.&lt;/P&gt;&lt;P data-unlink="true"&gt;Best regards,&lt;BR /&gt;&lt;BR /&gt;Greg&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2020 16:39:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunkd-Crash-Every-Ten-Minutes/m-p/531887#M6966</guid>
      <dc:creator>gearmstrong</dc:creator>
      <dc:date>2020-12-03T16:39:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunkd Crash Every Ten Minutes</title>
      <link>https://community.splunk.com/t5/Installation/Splunkd-Crash-Every-Ten-Minutes/m-p/531890#M6967</link>
      <description>&lt;P&gt;I have verified that the Secpol does not have "Lock Pages in Memory" enabled on this system.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2020 16:50:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunkd-Crash-Every-Ten-Minutes/m-p/531890#M6967</guid>
      <dc:creator>gearmstrong</dc:creator>
      <dc:date>2020-12-03T16:50:37Z</dc:date>
    </item>
    <item>
      <title>Splunkd Crash Every Ten Minutes</title>
      <link>https://community.splunk.com/t5/Installation/Splunkd-Crash-Every-Ten-Minutes/m-p/531892#M6968</link>
      <description>&lt;P&gt;May have Identified the source of the crash as SplunkAppForWebAnalytics Acceleration Job that 'fires' every ten minutes crashing the "BucketSummaryActorThread" but now need to figure out how to address it.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;ERROR SavedSplunker - savedsearch_id="nobody;SplunkAppForWebAnalytics;_ACCELERATE_DM_SplunkAppForWebAnalytics_Web_ACCELERATE_", message="The search job&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2020 16:59:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunkd-Crash-Every-Ten-Minutes/m-p/531892#M6968</guid>
      <dc:creator>gearmstrong</dc:creator>
      <dc:date>2020-12-03T16:59:10Z</dc:date>
    </item>
    <item>
      <title>Splunkd Crash Every Ten Minutes</title>
      <link>https://community.splunk.com/t5/Installation/Splunkd-Crash-Every-Ten-Minutes/m-p/531901#M6970</link>
      <description>&lt;P&gt;Found where similar issue was fixed in 8.0.2....&amp;nbsp; Can this be similar in any way to previous bug-fixes?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;PRE&gt;&lt;SPAN class="line"&gt;"https://docs.splunk.com/Documentation/Splunk/8.0.2/ReleaseNotes/Fixedissues","Search issues","2020-01-06","SPL-180268, SPL-177675","Crash in BucketSummaryActorThread for a specific summary directory, persists after removing"&lt;/SPAN&gt;

&lt;/PRE&gt;</description>
      <pubDate>Thu, 03 Dec 2020 18:22:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunkd-Crash-Every-Ten-Minutes/m-p/531901#M6970</guid>
      <dc:creator>gearmstrong</dc:creator>
      <dc:date>2020-12-03T18:22:27Z</dc:date>
    </item>
    <item>
      <title>Splunkd Crash Every Ten Minutes</title>
      <link>https://community.splunk.com/t5/Installation/Splunkd-Crash-Every-Ten-Minutes/m-p/531914#M6972</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Ok... I have finally isolated the individual Job that is Crashing the thread.&amp;nbsp; I would like to disable a scheduled job under Web Analytics called "&lt;/SPAN&gt;&lt;SPAN&gt;Generate Goal summary - Scheduled&lt;/SPAN&gt;&lt;SPAN&gt;"&amp;nbsp; as it is the culprit.&amp;nbsp; I ran it manually and it crashed.&amp;nbsp; I checked under Goals and do not see any configured and the WA_Goas.csv lookup is empty.&amp;nbsp; Under "Goals" "Setup" I do not see any Goals configured for any of our sites so I don't think it is used.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Here is the code for that job.... in case any of you can figure out if it is a bug with this App and 8.1.0.1 or if it is just bad code!&lt;BR /&gt;&lt;BR /&gt;| inputlookup WA_goals&lt;BR /&gt;| map maxsearches=10000 search="search tag=web eventtype=pageview site=\"$site$\"&lt;BR /&gt;| eval goal_id=\"$goal_id$\"&lt;BR /&gt;| eval goal_start=\"$start$\"&lt;BR /&gt;| eval goal_end=\"$end$\"&lt;BR /&gt;| rex field=goal_start mode=sed \"s/\*/%/g\"&lt;BR /&gt;| rex field=goal_end mode=sed \"s/\*/%/g\"&lt;BR /&gt;| lookup WA_sessions user AS user OUTPUT http_session,http_session_start,http_session_end,http_session_pageviews,http_session_duration,http_referer,http_referer_domain AS http_session_referrer_domain,http_referer_hostname AS http_session_referrer_hostname,http_session_channel&lt;BR /&gt;| where isnotnull(http_session)&lt;BR /&gt;| lookup user_agents http_user_agent&lt;BR /&gt;| eval ua_mobile=if(eventtype==\"ua-mobile\",'ua_device', \"\")&lt;BR /&gt;| bucket _time span=10m&lt;BR /&gt;| stats dc(http_session) AS Sessions,dc(user) AS Users,count(eval(like(uri,goal_start))) AS Entries,count(eval(like(uri,goal_end))) AS Completed by _time, site, goal_id, http_session_channel, http_session_referrer_domain,ua_family,ua_mobile,ua_os_family,goal_id&lt;BR /&gt;| eval goal_start=\"$start$\"&lt;BR /&gt;| eval goal_end=\"$end$\"&lt;BR /&gt;| collect index=goal_summary&lt;BR /&gt;"&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2020 19:50:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunkd-Crash-Every-Ten-Minutes/m-p/531914#M6972</guid>
      <dc:creator>gearmstrong</dc:creator>
      <dc:date>2020-12-03T19:50:40Z</dc:date>
    </item>
    <item>
      <title>Splunkd Crash Every Ten Minutes</title>
      <link>https://community.splunk.com/t5/Installation/Splunkd-Crash-Every-Ten-Minutes/m-p/532181#M6980</link>
      <description>&lt;P&gt;Job was just a coincidence in scheduling.&amp;nbsp; Crash still occurring.&amp;nbsp; See that it matches the Web Data Model Acceleration Cron Schedule.&amp;nbsp; Decided to try to perform a rebuild but crash still persists.&amp;nbsp; Does anyone have any other suggestions.... short of not using the WebAnalytics App?&amp;nbsp; This is a 'no-go' as customer uses this very extensively.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Configuration Settings &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;These settings can be changed by going to actions and selecting edit acceleration. Learn More&lt;/P&gt;&lt;P&gt;allow_old_summaries = true&lt;/P&gt;&lt;P&gt;allow_skew = 0&lt;/P&gt;&lt;P&gt;backfill_time = -&lt;/P&gt;&lt;P&gt;cron_schedule = 2,12,22,32,42,52 * * * *&lt;/P&gt;&lt;P&gt;earliest_time = -3mon&lt;/P&gt;&lt;P&gt;hunk.compression_codec = -&lt;/P&gt;&lt;P&gt;hunk.dfs_block_size = 0&lt;/P&gt;&lt;P&gt;hunk.file_format = -&lt;/P&gt;&lt;P&gt;manual_rebuilds = true&lt;/P&gt;&lt;P&gt;max_concurrent = 6&lt;/P&gt;&lt;P&gt;max_time = 3600&lt;/P&gt;&lt;P&gt;poll_buckets_until_maxtime = false&lt;/P&gt;&lt;P&gt;schedule_priority = highest&lt;/P&gt;&lt;P&gt;workload_pool = -&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2020 12:51:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunkd-Crash-Every-Ten-Minutes/m-p/532181#M6980</guid>
      <dc:creator>gearmstrong</dc:creator>
      <dc:date>2020-12-07T12:51:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunkd Crash Every Ten Minutes</title>
      <link>https://community.splunk.com/t5/Installation/Splunkd-Crash-Every-Ten-Minutes/m-p/532481#M6986</link>
      <description>&lt;P&gt;Hi Greg&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry about the issues.&lt;/P&gt;&lt;DIV&gt;I've updated the codebase now as I managed to reproduce the error. I've just published a new release to Splunkbase (2.2.5) although it is not vetted for Splunk Cloud yet, this might take a few days.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;There were some Python3 compatibility issues that were so minor they went through the basic checks. Unfortunately it meant the datamodel&amp;nbsp;wouldn't build every 10 minutes and that job crashed.&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Let me know if this works for you.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;A href="https://github.com/johanbjerke/SplunkAppForWebAnalytics/releases/tag/2.2.5" target="_blank"&gt;https://github.com/johanbjerke/SplunkAppForWebAnalytics/releases/tag/2.2.5&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;A href="https://splunkbase.splunk.com/app/2699/" target="_blank"&gt;https://splunkbase.splunk.com/app/2699/&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Kind&amp;nbsp;regards&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Johan&lt;/DIV&gt;</description>
      <pubDate>Wed, 09 Dec 2020 14:42:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunkd-Crash-Every-Ten-Minutes/m-p/532481#M6986</guid>
      <dc:creator>jbjerke_splunk</dc:creator>
      <dc:date>2020-12-09T14:42:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunkd Crash Every Ten Minutes</title>
      <link>https://community.splunk.com/t5/Installation/Splunkd-Crash-Every-Ten-Minutes/m-p/532527#M6989</link>
      <description>&lt;P&gt;Thank you so much.&amp;nbsp; Upgrading to 2.2.5 resolved the issue.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 20:23:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunkd-Crash-Every-Ten-Minutes/m-p/532527#M6989</guid>
      <dc:creator>gearmstrong</dc:creator>
      <dc:date>2020-12-09T20:23:55Z</dc:date>
    </item>
  </channel>
</rss>

