Monitoring Splunk

How to solve the error "mongodb has exhausted the system memory capacity" error ?

Upas02
Path Finder

HI,

I have a standalone Splunk setup in Windows.

I have started getting the mongodb has exhausted the system memory capacity error in my mongod.log , and in splunks.log , I'm getting KV Store initialization has failed which I am thinking is because of the Mongo DB memory issue.

Please suggest how I can solve this problem? I saw another thread which said to change KVStore memory size. But, I read somewhere that that is not recommended. Also, do not know whether that is a correct solution or now. Please let me know.

Details mongod.log as below -

2018-09-07T08:54:11.046Z F STORAGE  [conn9] MongoDB has exhausted the system memory capacity.
 2018-09-07T08:54:11.046Z F STORAGE  [conn9] Current Memory Status: { page_faults: 10422817, usagePageFileMB: 234, totalPageFileMB: 123515, availPageFileMB: 52, ramMB: 65191 }
 2018-09-07T08:54:11.046Z F STORAGE  [conn9] VirtualProtect for C:/Program Files/Splunk/var/lib/splunk/kvstore/mongo/local.1 chunk 4101 failed with errno:1455 The paging file is too small for this operation to complete. (chunk size is 67108864, address is 4014000000) in mongo::makeChunkWritable, terminating
 2018-09-07T08:54:11.046Z I -        [conn9] Fatal Assertion 16362
 2018-09-07T08:54:11.073Z I ACCESS   [conn194] Successfully authenticated as principal __system on local
 2018-09-07T08:54:11.185Z I CONTROL  [conn9] mongod.exe      index_collator_extension+0x146b13
 2018-09-07T08:54:11.185Z I CONTROL  [conn9] mongod.exe      index_collator_extension+0xfe14f
 2018-09-07T08:54:11.185Z I CONTROL  [conn9] mongod.exe      index_collator_extension+0xf0847
 2018-09-07T08:54:11.185Z I CONTROL  [conn9] mongod.exe      ???
 2018-09-07T08:54:11.185Z I CONTROL  [conn9] mongod.exe      ???
 2018-09-07T08:54:11.185Z I CONTROL  [conn9] mongod.exe      ???
 2018-09-07T08:54:11.185Z I CONTROL  [conn9] mongod.exe      ???
2018-09-07T08:54:11.185Z I CONTROL  [conn9] mongod.exe      index_collator_extension+0x450e38
 2018-09-07T08:54:11.185Z I CONTROL  [conn9] mongod.exe      index_collator_extension+0x10a6f3
 2018-09-07T08:54:11.185Z I CONTROL  [conn9] mongod.exe      index_collator_extension+0x1670f1
 2018-09-07T08:54:11.185Z I CONTROL  [conn9] mongod.exe      index_collator_extension+0x47fa0b
 2018-09-07T08:54:11.185Z I CONTROL  [conn9] mongod.exe      index_collator_extension+0x47fbb2
 2018-09-07T08:54:11.185Z I CONTROL  [conn9] KERNEL32.DLL    BaseThreadInitThunk+0x14
 2018-09-07T08:54:11.185Z I CONTROL  [conn9] 
 2018-09-07T08:54:11.185Z I -        [conn9] 
 ***aborting after fassert() failure
0 Karma

adonio
Ultra Champion
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...