Getting Data In

How to stop splunkd.exe from creating crash dump files under var\log\splunk on a universal forwarder?

sylim_splunk
Splunk Employee
Splunk Employee

On the universal forwarder, splunkd.exe is creating many crash dump files that are filling up disk space, which affects the services on the server. Please let me know if you have any configurations to disable crash dumping.

0 Karma
1 Solution

sylim_splunk
Splunk Employee
Splunk Employee

Crash dump by splunk provides a lot of useful information to troubleshoot the root case of the issues. We would like to recommend you to keep it enabled unless it affects the genuine services of the server due to the dump files.

Please find the information below for your reference;

View solution in original post

sylim_splunk
Splunk Employee
Splunk Employee

Crash dump by splunk provides a lot of useful information to troubleshoot the root case of the issues. We would like to recommend you to keep it enabled unless it affects the genuine services of the server due to the dump files.

Please find the information below for your reference;

Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...