<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunkd crash after some time with below errors- How do I fix? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunkd-crash-after-some-time-with-below-errors-How-do-I-fix/m-p/615502#M213905</link>
    <description>&lt;P&gt;I Agree on the points where you mentioned that is it is not relevant, but some how it is working for me .Let me explain why I think . I am installing apps like Event gen , Security essentials, CIM and my custome apps that have DM with Acceleration. What I believe is rather turning on everything at same time I should have wait on each step . I saw some search lag issues as I monitor my instance , after install and with old approach my RAM got sudden hike system hung and spluknd crashed .&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just changed my approach and things started working&amp;nbsp; ,Now I have turned on all inputs and I am not observing any crash from last 1 hour , DM are accelerating, Event gen is generating good amount of logs&amp;nbsp; &amp;nbsp;. Earlier it was failing after every 10 min&amp;nbsp;&lt;/P&gt;&lt;P&gt;on Ulimit it is permanently&amp;nbsp; set in&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;/etc/security/limits.conf&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
    <pubDate>Sat, 01 Oct 2022 16:46:26 GMT</pubDate>
    <dc:creator>vikasg</dc:creator>
    <dc:date>2022-10-01T16:46:26Z</dc:date>
    <item>
      <title>Splunkd crash after some time with below errors- How do I fix?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunkd-crash-after-some-time-with-below-errors-How-do-I-fix/m-p/615447#M213880</link>
      <description>&lt;P&gt;ERROR HttpListener [97417 TcpChannelThread] - Exception while processing request from x.x.x.x:63596 for /en-US/splunkd/__raw/services/search/shelper?output_mode=json&amp;amp;snippet=true&amp;amp;snippetEmbedJS=false&amp;amp;namespace=search&amp;amp;search=search%20i&amp;amp;useTypeahead=true&amp;amp;showCommandHelp=true&amp;amp;showCommandHistory=true&amp;amp;showFieldInfo=false&amp;amp;_=1664562934323: std::bad_alloc&lt;/P&gt;
&lt;P&gt;Any help please&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 19:30:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunkd-crash-after-some-time-with-below-errors-How-do-I-fix/m-p/615447#M213880</guid>
      <dc:creator>vikasg</dc:creator>
      <dc:date>2022-09-30T19:30:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunkd crash after some time with below errors- How do I fix?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunkd-crash-after-some-time-with-below-errors-How-do-I-fix/m-p/615485#M213895</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/239146"&gt;@vikasg&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;every time you have a crash I hint to open a case to Splunk Support, for your support and to highlight a possible issue!&lt;/P&gt;&lt;P&gt;Anyway, some question to better undertand your situation:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;after the chash, does your Splunk server normally work?&lt;/LI&gt;&lt;LI&gt;have you the minimum hardware resources for your Splunk Server?&lt;/LI&gt;&lt;LI&gt;Are you speaking of a Splunk Server or a Universal Forwarder?&lt;/LI&gt;&lt;LI&gt;If a Splunk Server, what's its role?&lt;/LI&gt;&lt;LI&gt;It's a Linux or Windows Operative System?&lt;/LI&gt;&lt;LI&gt;Ciao.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sat, 01 Oct 2022 06:05:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunkd-crash-after-some-time-with-below-errors-How-do-I-fix/m-p/615485#M213895</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-10-01T06:05:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunkd crash after some time with below errors- How do I fix?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunkd-crash-after-some-time-with-below-errors-How-do-I-fix/m-p/615492#M213899</link>
      <description>&lt;P&gt;Thank you for the response . This is latest splunk that 9.0.1 and Single Linux box for POC . It has 32 GB RAM with 16 CPU , this is SH come indexer&lt;/P&gt;&lt;P&gt;Ulimit is set as per recommendation .&lt;/P&gt;&lt;P&gt;THP is disabled&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 01 Oct 2022 08:52:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunkd-crash-after-some-time-with-below-errors-How-do-I-fix/m-p/615492#M213899</guid>
      <dc:creator>vikasg</dc:creator>
      <dc:date>2022-10-01T08:52:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunkd crash after some time with below errors- How do I fix?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunkd-crash-after-some-time-with-below-errors-How-do-I-fix/m-p/615497#M213901</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/239146"&gt;@vikasg&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;your hardware and your configuration (ulimit and THP) are correct, so I hint to make a Diag (they surely will ask you) and to open a case to Splunk Support.&lt;/P&gt;&lt;P&gt;They will be able to analize your system to understand what happened&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sat, 01 Oct 2022 13:33:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunkd-crash-after-some-time-with-below-errors-How-do-I-fix/m-p/615497#M213901</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-10-01T13:33:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunkd crash after some time with below errors- How do I fix?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunkd-crash-after-some-time-with-below-errors-How-do-I-fix/m-p/615498#M213902</link>
      <description>&lt;P&gt;Since it is POC and I am using trial license for 60 days , I do not think I can open support case on this trial license .&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am digging this further , found few things which cause the issue&lt;/P&gt;&lt;P&gt;Finding&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) I have moved to older Splunk version like to 8.2.6.1&lt;/P&gt;&lt;P&gt;2) Under ulimit I set maximum memory to like 80% of the over all&amp;nbsp;&lt;/P&gt;&lt;P&gt;3) after installation I gave like 1 hour to the machine to settle , then start ingesting data with low rate&amp;nbsp;&lt;/P&gt;&lt;P&gt;4) NOw I am increasing data flow rate&lt;/P&gt;&lt;P&gt;5) Since it was POC so I ran splunk service with root user only , but now created splunk user and set ulimit accordingly&amp;nbsp;&lt;/P&gt;&lt;P&gt;6) Tweaked some data model acceleration which was were aggressive earlier&amp;nbsp; &amp;nbsp;(actually same machine is acting as indexer and SH ) so better to start slow and gradually increase&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this will help someone , I am still not accepting my own answer as I am sure I will have few more findings&amp;nbsp; which I will add to this comment&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 01 Oct 2022 14:07:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunkd-crash-after-some-time-with-below-errors-How-do-I-fix/m-p/615498#M213902</guid>
      <dc:creator>vikasg</dc:creator>
      <dc:date>2022-10-01T14:07:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunkd crash after some time with below errors- How do I fix?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunkd-crash-after-some-time-with-below-errors-How-do-I-fix/m-p/615499#M213903</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/239146"&gt;@vikasg&lt;/a&gt;.&lt;/P&gt;&lt;P&gt;if you are a customer, you can ask to Splunk Sales to follow your case, if you are a Splunk partner you can ask to your Splunk Channel Manager to do the same thing! in other words you will not be abandoned!&lt;/P&gt;&lt;P&gt;Anyway:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;1) I have moved to older Splunk version like to 8.2.6.1&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;it should not be relevant,&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) Under ulimit I set maximum memory to like 80% of the over all&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;you have much more memeory than requested, so it shouldn't be the problem&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3) after installation I gave like 1 hour to the machine to settle , then start ingesting data with low rate&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;not relevant&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;4) NOw I am increasing data flow rate&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;not relevant&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;5) Since it was POC so I ran splunk service with root user only , but now created splunk user and set ulimit accordingly&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;are you sure to set the correct ulimit?&lt;/LI&gt;&lt;LI&gt;I encountered some problems about this: did you used ilimit -c or changed the values in /etc/security/limits.conf?&lt;/LI&gt;&lt;LI&gt;the correct one is the second:&lt;UL&gt;&lt;LI&gt;&lt;P&gt;/etc/security/limits.conf&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;user_name hard nofile 8192&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;user_name soft nofile 8192&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;6) Tweaked some data model acceleration which was were aggressive earlier&amp;nbsp; &amp;nbsp;(actually same machine is acting as indexer and SH ) so better to start slow and gradually increase&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;your hardware should give you all the requested performances&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Check if it was a momentary lap of reason&amp;nbsp;(to quote Pink Floyd!) or it's something repeated.&lt;/P&gt;&lt;P&gt;In other words, monitor your system to understand if the situation will repeat.&lt;/P&gt;&lt;P&gt;You can also check your system using the Splunk Monitoring Console App (default Splunk)&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sat, 01 Oct 2022 14:26:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunkd-crash-after-some-time-with-below-errors-How-do-I-fix/m-p/615499#M213903</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-10-01T14:26:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunkd crash after some time with below errors- How do I fix?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunkd-crash-after-some-time-with-below-errors-How-do-I-fix/m-p/615502#M213905</link>
      <description>&lt;P&gt;I Agree on the points where you mentioned that is it is not relevant, but some how it is working for me .Let me explain why I think . I am installing apps like Event gen , Security essentials, CIM and my custome apps that have DM with Acceleration. What I believe is rather turning on everything at same time I should have wait on each step . I saw some search lag issues as I monitor my instance , after install and with old approach my RAM got sudden hike system hung and spluknd crashed .&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just changed my approach and things started working&amp;nbsp; ,Now I have turned on all inputs and I am not observing any crash from last 1 hour , DM are accelerating, Event gen is generating good amount of logs&amp;nbsp; &amp;nbsp;. Earlier it was failing after every 10 min&amp;nbsp;&lt;/P&gt;&lt;P&gt;on Ulimit it is permanently&amp;nbsp; set in&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;/etc/security/limits.conf&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Sat, 01 Oct 2022 16:46:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunkd-crash-after-some-time-with-below-errors-How-do-I-fix/m-p/615502#M213905</guid>
      <dc:creator>vikasg</dc:creator>
      <dc:date>2022-10-01T16:46:26Z</dc:date>
    </item>
  </channel>
</rss>

