All Apps and Add-ons

ADMon ldap_get_values error

rtadams89
Contributor

I just updated our Splunk Universal Forwarder that is running admon from 4.2.3 to 5.0.4. After the upgrade, admon is continuing to log events, but I also am getting about 12 of these errors every minute from the forwarder running admon:

09-18-2013 01:35:02.621 -0500 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe" -index activedirectory" splunk-admon - ProcessMessage: ldap_get_values error

Since admon appears to be working, I'm not sure what the errors indicate.

As of 4/27/14, my support case on the issue is still "Waiting on Dev"...

Tags (1)
0 Karma

cpetterborg
SplunkTrust
SplunkTrust

We are getting these errors on several servers, and have had 3 servers become unresponsive due to the problem. Here is a message from one of the servers (running Win Server 2008 64-bit):

Log Name: System
Source: Microsoft-Windows-Resource-Exhaustion-Detector
Date: 3/25/2014 11:19:56 AM
Event ID: 2004
Task Category: Resource Exhaustion Diagnosis Events
Level: Warning
Keywords: Events related to exhaustion of system commit limit (virtual memory).
User: SYSTEM
Computer: W12620.#########.###
Description:
Windows successfully diagnosed a low virtual memory condition. The following programs consumed the most virtual memory: splunk-admon.exe (564) consumed 15444475904 bytes, svchost.exe (856) consumed 276242432 bytes, and Microsoft.Dynamics.Integration.Service.exe (1512) consumed 208461824 bytes.

0 Karma

rtadams89
Contributor

Still waiting on support...

0 Karma

CSabhaya
Engager

I am also receiving the same errors. did anyone find any solution ?

0 Karma

mad4wknds
Path Finder

I am receiving the same errors and will continue to look for a solution.

0 Karma

rtadams89
Contributor

As of 11/12/2013, Splunk support still does not have a fix or known root cause.

0 Karma

awsdcuser
Explorer

I am receiving the same errors after an install of a UF (5.0.4) on a DC. Did you find a solution to this? Thanks.

0 Karma
Get Updates on the Splunk Community!

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...