Deployment Architecture

I got a "Streamed search execute failed because" warning message in Splunk? What does this mean?

Splunk Employee
Splunk Employee

During one of my searches, I got this following error message "Streamed search execute failed because: St9bad_alloc". Any ideas on why it would occur and what it means?


bad_alloc usually means it can't assign memory space for what it needs.

Whats your memory look like on your search head and indexers?


Any error along the lines of "Streamed search execute failed ..." is a distributed search error. You'll find this error on the search head, however, it is pointing to some issue at the search peer. If you have multiple search peers, you'll need to investigate which peer triggered this error and then go deeper into why the error was triggered.

The St9bad_alloc might have something to do with a memory/resource issue at the search peer. Need more context.

State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!