Getting Data In

Restarting a universal forwarder on AIX, why do I get error "ulimit - Splunk may not work due to small data segment/resident memory limit"?

akdake
Explorer

Hi,

I get the following error when I restart our universal forwarder for AIX,

05-24-2016 18:06:26.872 +0800 INFO  loader - Splunkd starting (build 272667).
...
05-24-2016 18:06:31.178 +0800 WARN  DateParserVerbose - Failed to parse timestamp. Defaulting to timestamp of previous event (Tue May 24 11:02:48 2016). Context: FileClassifier /etc/aixmibd.conf
05-24-2016 18:06:32.686 +0800 ERROR PropertiesMapConfig - Failed to save stanza [/etc/aixmibd.conf_Tue_May_24_18:06:31_2016_1121352529] (user: , app: , root: /opt/splunkforwarder/etc) to app learned: bad allocation
05-24-2016 18:06:34.475 +0800 ERROR PropertiesMapConfig - Failed to save stanza [/etc/binld.cnf_Tue_May_24_18:06:33_2016_1082875830] (user: , app: , root: /opt/splunkforwarder/etc) to app learned: bad allocation
05-24-2016 18:06:36.294 +0800 ERROR PropertiesMapConfig - Failed to save stanza [/etc/cdromd.conf_Tue_May_24_18:06:35_2016_793076919] (user: , app: , root: /opt/splunkforwarder/etc) to app learned: bad allocation
05-24-2016 18:06:38.105 +0800 ERROR PropertiesMapConfig - Failed to save stanza [/etc/dhcpcd.ini_Tue_May_24_18:06:37_2016_566613028] (user: , app: , root: /opt/splunkforwarder/etc) to app learned: bad allocation
....
05-24-2016 18:06:44.915 +0800 INFO  ulimit - Limit: virtual address space size: unlimited
05-24-2016 18:06:44.915 +0800 INFO  ulimit - Limit: data segment size: 134217728 bytes [hard maximum: unlimited]
05-24-2016 18:06:44.915 +0800 WARN  ulimit - Splunk may not work due to small data segment limit!
05-24-2016 18:06:44.915 +0800 INFO  ulimit - Limit: resident memory size: 33554432 bytes [hard maximum: unlimited]
05-24-2016 18:06:44.915 +0800 WARN  ulimit - Splunk may not work due to small resident memory size limit!
....

Any ideas for the ERROR? TKS

0 Karma
1 Solution

ddrillic
Ultra Champion

Very similar issue at Why is Splunk is crashing on my AIX system and getting "bad allocation" errors in the splunkd.log?

It says -

alt text

It does say it clearly in the warnings -
WARN ulimit - Splunk may not work due to small data segment limit!

View solution in original post

ddrillic
Ultra Champion

Very similar issue at Why is Splunk is crashing on my AIX system and getting "bad allocation" errors in the splunkd.log?

It says -

alt text

It does say it clearly in the warnings -
WARN ulimit - Splunk may not work due to small data segment limit!

Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...