<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why does my Splunk server keep crashing? in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-does-my-Splunk-server-keep-crashing/m-p/405440#M3465</link>
    <description>&lt;P&gt;thanks for the super quick answer. we have the same issue with 6.6.3. Did you find an issue number or something for this one so i can trace it back to my version's known issue documentation?&lt;/P&gt;</description>
    <pubDate>Tue, 24 Jul 2018 15:00:37 GMT</pubDate>
    <dc:creator>tkrishnan</dc:creator>
    <dc:date>2018-07-24T15:00:37Z</dc:date>
    <item>
      <title>Why does my Splunk server keep crashing?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-does-my-Splunk-server-keep-crashing/m-p/405429#M3454</link>
      <description>&lt;P&gt;-bash-4.1$ cat crash-2018-05-21-09:41:12.log&lt;BR /&gt;
[build fa31da744b51] 2018-05-21 09:41:12&lt;BR /&gt;
Received fatal signal 6 (Aborted).&lt;BR /&gt;
 Cause:&lt;BR /&gt;
   Signal sent by PID 12969 running under UID 18002.&lt;BR /&gt;
 Crashing thread: DistributedSearchResultCollectorThread&lt;BR /&gt;
 Registers:&lt;BR /&gt;
    RIP:  [0x00007FA78E16B495] gsignal + 53 (libc.so.6 + 0x32495)&lt;BR /&gt;
    RDI:  [0x00000000000032A9]&lt;BR /&gt;
    RSI:  [0x00000000000032C9]&lt;BR /&gt;
    RBP:  [0x00007FA7916AEC30]&lt;BR /&gt;
    RSP:  [0x00007FA78B5FEA08]&lt;BR /&gt;
    RAX:  [0x0000000000000000]&lt;BR /&gt;
    RBX:  [0x00007FA7887FD000]&lt;BR /&gt;
    RCX:  [0xFFFFFFFFFFFFFFFF]&lt;BR /&gt;
    RDX:  [0x0000000000000006]&lt;BR /&gt;
    R8:  [0x0000000000000200]&lt;BR /&gt;
    R9:  [0xFEFEFEFEFEFEFEFF]&lt;BR /&gt;
    R10:  [0x0000000000000008]&lt;BR /&gt;
    R11:  [0x0000000000000206]&lt;BR /&gt;
    R12:  [0x00007FA7915F37C6]&lt;BR /&gt;
    R13:  [0x00007FA791793680]&lt;BR /&gt;
    R14:  [0x00007FA78B688010]&lt;BR /&gt;
    R15:  [0x00007FA78B5FED10]&lt;BR /&gt;
    EFL:  [0x0000000000000206]&lt;BR /&gt;
    TRAPNO:  [0x0000000000000000]&lt;BR /&gt;
    ERR:  [0x0000000000000000]&lt;BR /&gt;
    CSGSFS:  [0x0000000000000033]&lt;BR /&gt;
    OLDMASK:  [0x0000000000000000]&lt;/P&gt;

&lt;P&gt;OS: Linux&lt;BR /&gt;
 Arch: x86-64&lt;/P&gt;

&lt;P&gt;Backtrace (PIC build):&lt;BR /&gt;
  [0x00007FA78E16B495] gsignal + 53 (libc.so.6 + 0x32495)&lt;BR /&gt;
  [0x00007FA78E16CC75] abort + 373 (libc.so.6 + 0x33C75)&lt;BR /&gt;
  [0x00007FA78E16460E] ? (libc.so.6 + 0x2B60E)&lt;BR /&gt;
  [0x00007FA78E1646D0] __assert_perror_fail + 0 (libc.so.6 + 0x2B6D0)&lt;BR /&gt;
  [0x00007FA7909B0E6F] _ZN9EventLoop3addEP8PolledFd18PollableDescriptorj + 591 (splunkd + 0x1251E6F)&lt;BR /&gt;
  [0x00007FA7909B2BAE] _ZN19InThreadActorNotifyC2EP9EventLoop + 46 (splunkd + 0x1253BAE)&lt;BR /&gt;
  [0x00007FA7909B2E50] _ZN9EventLoop3runEv + 96 (splunkd + 0x1253E50)&lt;BR /&gt;
  [0x00007FA790A6DAF0] _ZN15TcpOutboundLoop3runEv + 16 (splunkd + 0x130EAF0)&lt;BR /&gt;
  [0x00007FA78FFBFF05] _ZN21EventLoopRunnerThread4mainEv + 37 (splunkd + 0x860F05)&lt;BR /&gt;
  [0x00007FA790A6EB1F] _ZN6Thread8callMainEPv + 111 (splunkd + 0x130FB1F)&lt;BR /&gt;
  [0x00007FA78E4D4AA1] ? (libpthread.so.0 + 0x7AA1)&lt;BR /&gt;
  [0x00007FA78E221BCD] clone + 109 (libc.so.6 + 0xE8BCD)&lt;BR /&gt;
 Linux /  / 2.6.32-696.28.1.el6.x86_64 / #1 SMP Thu Apr 26 04:27:41 EDT 2018 / x86_64&lt;BR /&gt;
 Last few lines of stderr (may contain info on assertion failure, but also could be old):&lt;BR /&gt;
    2018-05-21 07:50:44.714 -0400 splunkd started (build fa31da744b51)&lt;BR /&gt;
    2018-05-21 08:05:58.776 -0400 splunkd started (build fa31da744b51)&lt;BR /&gt;
    splunkd: /home/build/build-src/minty/src/util/EventLoop.cpp:843: void EventLoop::add(PolledFd*, PollableDescriptor, events_mask_t): Assertion `fd.valid()' failed.&lt;BR /&gt;
    2018-05-21 08:15:40.920 -0400 splunkd started (build fa31da744b51)&lt;BR /&gt;
    2018-05-21 08:30:58.927 -0400 splunkd started (build fa31da744b51)&lt;BR /&gt;
    2018-05-21 08:40:36.969 -0400 splunkd started (build fa31da744b51)&lt;BR /&gt;
    2018-05-21 08:50:37.156 -0400 splunkd started (build fa31da744b51)&lt;BR /&gt;
    2018-05-21 09:05:55.191 -0400 splunkd started (build fa31da744b51)&lt;BR /&gt;
    2018-05-21 09:25:37.188 -0400 splunkd started (build fa31da744b51)&lt;BR /&gt;
    2018-05-21 09:35:45.231 -0400 splunkd started (build fa31da744b51)&lt;/P&gt;

&lt;P&gt;/etc/redhat-release: Red Hat Enterprise Linux Server release 6.9 (Santiago)&lt;BR /&gt;
 glibc version: 2.12&lt;BR /&gt;
 glibc release: stable&lt;BR /&gt;
Last errno: 23&lt;BR /&gt;
Threads running: 16&lt;BR /&gt;
Runtime: 327.200553s&lt;BR /&gt;
argv: [splunkd -p 8089 restart]&lt;BR /&gt;
Process renamed: [splunkd pid=6741] splunkd -p 8089 restart [process-runner]&lt;BR /&gt;
Process renamed: [splunkd pid=6741] search --id=scheduler_&lt;EM&gt;nobody&lt;/EM&gt;&lt;EM&gt;f5&lt;/EM&gt;_RMD54f4818d5a227023d_at_1526910000_56 --maxbuckets=0 --ttl=600 --maxout=500000 --maxtime=8640000 --lookups=1 --reduce_freq=10 --user=splunk-system-user --pro --roles=admin:splunk-system-role&lt;/P&gt;

&lt;P&gt;Regex JIT disabled due to SELinux&lt;/P&gt;

&lt;P&gt;using CLOCK_MONOTONIC&lt;BR /&gt;
Preforked process=0/65: process_runtime_msec=606, search=0/124, search_runtime_msec=592, new_user=N, export_search=N, args_size=256, completed_searches=0, user_changes=0, cache_rotations=0&lt;/P&gt;

&lt;P&gt;Thread: "DistributedSearchResultCollectorThread", did_join=0, ready_to_run=Y, main_thread=N&lt;BR /&gt;
First 8 bytes of Thread token @0x7fa78ab1ce10:&lt;BR /&gt;
00000000  00 f7 5f 8b a7 7f 00 00                           |.._.....|&lt;BR /&gt;
00000008&lt;/P&gt;

&lt;P&gt;x86 CPUID registers:&lt;BR /&gt;
         0: 0000000D 756E6547 6C65746E 49656E69&lt;BR /&gt;
         1: 000206D2 0A040800 9E982203 1F8BFBFF&lt;BR /&gt;
         2: 76036301 00F0B5FF 00000000 00C10000&lt;BR /&gt;
         3: 00000000 00000000 00000000 00000000&lt;BR /&gt;
         4: 00000000 00000000 00000000 00000000&lt;BR /&gt;
         5: 00000000 00000000 00000000 00000000&lt;BR /&gt;
         6: 00000077 00000002 00000009 00000000&lt;BR /&gt;
         7: 00000000 00000000 00000000 00000000&lt;BR /&gt;
         8: 00000000 00000000 00000000 00000000&lt;BR /&gt;
         9: 00000000 00000000 00000000 00000000&lt;BR /&gt;
         A: 07300401 0000007F 00000000 00000000&lt;BR /&gt;
         B: 00000000 00000000 000000CD 0000000A&lt;BR /&gt;
         C: 00000000 00000000 00000000 00000000&lt;BR /&gt;
         &lt;span class="lia-unicode-emoji" title=":anguished_face:"&gt;😧&lt;/span&gt; 00000000 00000000 00000000 00000000&lt;BR /&gt;
  80000000: 80000008 00000000 00000000 00000000&lt;BR /&gt;
  80000001: 00000000 00000000 00000001 28100800&lt;BR /&gt;
  80000002: 65746E49 2952286C 6F655820 2952286E&lt;BR /&gt;
  80000003: 55504320 2D354520 37383632 33762057&lt;BR /&gt;
  80000004: 33204020 4730312E 00007A48 00000000&lt;BR /&gt;
  80000005: 00000000 00000000 00000000 00000000&lt;BR /&gt;
  80000006: 00000000 00000000 01006040 00000000&lt;BR /&gt;
  80000007: 00000000 00000000 00000000 00000100&lt;BR /&gt;
  80000008: 00003028 00000000 00000000 00000000&lt;BR /&gt;
terminating...&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:35:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-does-my-Splunk-server-keep-crashing/m-p/405429#M3454</guid>
      <dc:creator>dmitri47</dc:creator>
      <dc:date>2020-09-29T19:35:38Z</dc:date>
    </item>
    <item>
      <title>Re: Why does my Splunk server keep crashing?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-does-my-Splunk-server-keep-crashing/m-p/405430#M3455</link>
      <description>&lt;P&gt;I would go to Support ... &lt;/P&gt;</description>
      <pubDate>Mon, 21 May 2018 17:05:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-does-my-Splunk-server-keep-crashing/m-p/405430#M3455</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2018-05-21T17:05:25Z</dc:date>
    </item>
    <item>
      <title>Re: Why does my Splunk server keep crashing?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-does-my-Splunk-server-keep-crashing/m-p/405431#M3456</link>
      <description>&lt;P&gt;Yeah... Will post if and when I get resolution. Gooogle says that a bunch of other users have had this issue. Why can't splunk fix it? &lt;/P&gt;</description>
      <pubDate>Mon, 21 May 2018 17:13:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-does-my-Splunk-server-keep-crashing/m-p/405431#M3456</guid>
      <dc:creator>dmitri47</dc:creator>
      <dc:date>2018-05-21T17:13:21Z</dc:date>
    </item>
    <item>
      <title>Re: Why does my Splunk server keep crashing?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-does-my-Splunk-server-keep-crashing/m-p/405432#M3457</link>
      <description>&lt;P&gt;It appears you have SE Linux enabled, have you followed:&lt;BR /&gt;
&lt;A href="https://github.com/doksu/selinux_policy_for_splunk"&gt;https://github.com/doksu/selinux_policy_for_splunk&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 May 2018 18:10:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-does-my-Splunk-server-keep-crashing/m-p/405432#M3457</guid>
      <dc:creator>solarboyz1</dc:creator>
      <dc:date>2018-05-21T18:10:45Z</dc:date>
    </item>
    <item>
      <title>Re: Why does my Splunk server keep crashing?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-does-my-Splunk-server-keep-crashing/m-p/405433#M3458</link>
      <description>&lt;P&gt;What is the version of Splunk, plus the size of your environment?&lt;/P&gt;</description>
      <pubDate>Mon, 21 May 2018 18:18:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-does-my-Splunk-server-keep-crashing/m-p/405433#M3458</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2018-05-21T18:18:42Z</dc:date>
    </item>
    <item>
      <title>Re: Why does my Splunk server keep crashing?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-does-my-Splunk-server-keep-crashing/m-p/405434#M3459</link>
      <description>&lt;P&gt;We have 4 enclaves and Splunk on all 4. All have the same SE Linux set, but issues only on 1 server.&lt;/P&gt;</description>
      <pubDate>Mon, 21 May 2018 18:25:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-does-my-Splunk-server-keep-crashing/m-p/405434#M3459</guid>
      <dc:creator>dmitri47</dc:creator>
      <dc:date>2018-05-21T18:25:50Z</dc:date>
    </item>
    <item>
      <title>Re: Why does my Splunk server keep crashing?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-does-my-Splunk-server-keep-crashing/m-p/405435#M3460</link>
      <description>&lt;P&gt;This first started when I upgraded from Splunk 7.0.3 to 7.1&lt;/P&gt;

&lt;P&gt;After noticing that this one server (a Splunk SearchHead) was crashing every 3-5 mins, I downgraded that whole environment from 7.1 to 7.0.3 (like 8-9 servers total)&lt;/P&gt;

&lt;P&gt;It was fine for 1-2 days and now is crashing all o the time.&lt;BR /&gt;
Other enclaves work just fine = Splunk 7.1 is stable&lt;/P&gt;

&lt;P&gt;Size = 1 CM  server, 2 indexers, 4 searchheads, up to 150 splunkforwarders&lt;/P&gt;</description>
      <pubDate>Mon, 21 May 2018 18:29:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-does-my-Splunk-server-keep-crashing/m-p/405435#M3460</guid>
      <dc:creator>dmitri47</dc:creator>
      <dc:date>2018-05-21T18:29:38Z</dc:date>
    </item>
    <item>
      <title>Re: Why does my Splunk server keep crashing?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-does-my-Splunk-server-keep-crashing/m-p/405436#M3461</link>
      <description>&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/290645/why-is-our-splunk-624-forwarder-on-linux-crashing.html" target="_blank"&gt;https://answers.splunk.com/answers/290645/why-is-our-splunk-624-forwarder-on-linux-crashing.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Splunk 6.2.4 seems to have introduced a bug that causes splunkd to crash when a monitor watches for files that may be deleted (maybe too fast ?)&lt;/P&gt;

&lt;P&gt;I see in your output that the crash is related with the Nmon Performance Monitor:&lt;/P&gt;

&lt;P&gt;WatchedTailFile-WatchedFileState: path="/opt/splunkforwarder/var/run/nmon/var/csv_repository/Dymas_24_JUL_2015_053319_FILE_444882_20150724070843.nmon.csv", flags=0x24003&lt;BR /&gt;
The crash is not directly caused by Nmon App, until recently the processing steps used to create csv files in the same directory than splunk watches for, in some cases empty files could be created and deleted by nmon2csv converters, which causes splunkd in 6.2.4 to crash. (which is totally unexpected and wasn't the case before)&lt;/P&gt;

&lt;P&gt;I have released on 5 august 2014 an hotfix release with a workaround to manage this, now files are moved from a working directory to final directory splunk watches for, which solves the issue from splunkd.&lt;/P&gt;

&lt;P&gt;Please update to Nmon Perf Monitor 1.6.04 and your problem will be solved.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:35:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-does-my-Splunk-server-keep-crashing/m-p/405436#M3461</guid>
      <dc:creator>dmitri47</dc:creator>
      <dc:date>2020-09-29T19:35:54Z</dc:date>
    </item>
    <item>
      <title>Re: Why does my Splunk server keep crashing?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-does-my-Splunk-server-keep-crashing/m-p/405437#M3462</link>
      <description>&lt;P&gt;Seems that we had this issue back since 6.2.4, fixed since then, and broken again with 7.x somehow... SMH&lt;/P&gt;</description>
      <pubDate>Mon, 21 May 2018 18:49:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-does-my-Splunk-server-keep-crashing/m-p/405437#M3462</guid>
      <dc:creator>dmitri47</dc:creator>
      <dc:date>2018-05-21T18:49:11Z</dc:date>
    </item>
    <item>
      <title>Re: Why does my Splunk server keep crashing?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-does-my-Splunk-server-keep-crashing/m-p/405438#M3463</link>
      <description>&lt;P&gt;@dmitri47 did you get anywhere with this one? Heard anything from Support ?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jul 2018 14:48:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-does-my-Splunk-server-keep-crashing/m-p/405438#M3463</guid>
      <dc:creator>tkrishnan</dc:creator>
      <dc:date>2018-07-24T14:48:18Z</dc:date>
    </item>
    <item>
      <title>Re: Why does my Splunk server keep crashing?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-does-my-Splunk-server-keep-crashing/m-p/405439#M3464</link>
      <description>&lt;P&gt;Soooo... There was a known issue in Splunk 7.0.3 and the upgrade to Splunk 7.1.1 fixed it.&lt;BR /&gt;
Has been working well since.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jul 2018 14:53:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-does-my-Splunk-server-keep-crashing/m-p/405439#M3464</guid>
      <dc:creator>SithLord</dc:creator>
      <dc:date>2018-07-24T14:53:13Z</dc:date>
    </item>
    <item>
      <title>Re: Why does my Splunk server keep crashing?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-does-my-Splunk-server-keep-crashing/m-p/405440#M3465</link>
      <description>&lt;P&gt;thanks for the super quick answer. we have the same issue with 6.6.3. Did you find an issue number or something for this one so i can trace it back to my version's known issue documentation?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jul 2018 15:00:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-does-my-Splunk-server-keep-crashing/m-p/405440#M3465</guid>
      <dc:creator>tkrishnan</dc:creator>
      <dc:date>2018-07-24T15:00:37Z</dc:date>
    </item>
    <item>
      <title>Re: Why does my Splunk server keep crashing?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-does-my-Splunk-server-keep-crashing/m-p/405441#M3466</link>
      <description>&lt;P&gt;I would look here:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.1.1/ReleaseNotes/Fixedissues"&gt;http://docs.splunk.com/Documentation/Splunk/7.1.1/ReleaseNotes/Fixedissues&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Fixed issues:&lt;/P&gt;

&lt;P&gt;2018-05-18  SPL-154138, SPL-154542, SPL-154544, FAST-9662   Searches with multikv extraction use too much memory: potentially orders of magnitude more than previous versions.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jul 2018 15:06:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-does-my-Splunk-server-keep-crashing/m-p/405441#M3466</guid>
      <dc:creator>SithLord</dc:creator>
      <dc:date>2018-07-24T15:06:46Z</dc:date>
    </item>
    <item>
      <title>Re: Why does my Splunk server keep crashing?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-does-my-Splunk-server-keep-crashing/m-p/405442#M3467</link>
      <description>&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.1.2/ReleaseNotes/Fixedissues"&gt;http://docs.splunk.com/Documentation/Splunk/7.1.2/ReleaseNotes/Fixedissues&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jul 2018 15:08:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-does-my-Splunk-server-keep-crashing/m-p/405442#M3467</guid>
      <dc:creator>SithLord</dc:creator>
      <dc:date>2018-07-24T15:08:06Z</dc:date>
    </item>
    <item>
      <title>Re: Why does my Splunk server keep crashing?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-does-my-Splunk-server-keep-crashing/m-p/405443#M3468</link>
      <description>&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.1.2/ReleaseNotes/Fixedissues"&gt;http://docs.splunk.com/Documentation/Splunk/7.1.2/ReleaseNotes/Fixedissues&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jul 2018 15:08:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-does-my-Splunk-server-keep-crashing/m-p/405443#M3468</guid>
      <dc:creator>SithLord</dc:creator>
      <dc:date>2018-07-24T15:08:13Z</dc:date>
    </item>
  </channel>
</rss>

