Getting Data In

Restarting a universal forwarder on AIX, why do I get error "ulimit - Splunk may not work due to small data segment/resident memory limit"?

akdake
Explorer

Hi,

I get the following error when I restart our universal forwarder for AIX,

05-24-2016 18:06:26.872 +0800 INFO  loader - Splunkd starting (build 272667).
...
05-24-2016 18:06:31.178 +0800 WARN  DateParserVerbose - Failed to parse timestamp. Defaulting to timestamp of previous event (Tue May 24 11:02:48 2016). Context: FileClassifier /etc/aixmibd.conf
05-24-2016 18:06:32.686 +0800 ERROR PropertiesMapConfig - Failed to save stanza [/etc/aixmibd.conf_Tue_May_24_18:06:31_2016_1121352529] (user: , app: , root: /opt/splunkforwarder/etc) to app learned: bad allocation
05-24-2016 18:06:34.475 +0800 ERROR PropertiesMapConfig - Failed to save stanza [/etc/binld.cnf_Tue_May_24_18:06:33_2016_1082875830] (user: , app: , root: /opt/splunkforwarder/etc) to app learned: bad allocation
05-24-2016 18:06:36.294 +0800 ERROR PropertiesMapConfig - Failed to save stanza [/etc/cdromd.conf_Tue_May_24_18:06:35_2016_793076919] (user: , app: , root: /opt/splunkforwarder/etc) to app learned: bad allocation
05-24-2016 18:06:38.105 +0800 ERROR PropertiesMapConfig - Failed to save stanza [/etc/dhcpcd.ini_Tue_May_24_18:06:37_2016_566613028] (user: , app: , root: /opt/splunkforwarder/etc) to app learned: bad allocation
....
05-24-2016 18:06:44.915 +0800 INFO  ulimit - Limit: virtual address space size: unlimited
05-24-2016 18:06:44.915 +0800 INFO  ulimit - Limit: data segment size: 134217728 bytes [hard maximum: unlimited]
05-24-2016 18:06:44.915 +0800 WARN  ulimit - Splunk may not work due to small data segment limit!
05-24-2016 18:06:44.915 +0800 INFO  ulimit - Limit: resident memory size: 33554432 bytes [hard maximum: unlimited]
05-24-2016 18:06:44.915 +0800 WARN  ulimit - Splunk may not work due to small resident memory size limit!
....

Any ideas for the ERROR? TKS

0 Karma
1 Solution

ddrillic
Ultra Champion

Very similar issue at Why is Splunk is crashing on my AIX system and getting "bad allocation" errors in the splunkd.log?

It says -

alt text

It does say it clearly in the warnings -
WARN ulimit - Splunk may not work due to small data segment limit!

View solution in original post

ddrillic
Ultra Champion

Very similar issue at Why is Splunk is crashing on my AIX system and getting "bad allocation" errors in the splunkd.log?

It says -

alt text

It does say it clearly in the warnings -
WARN ulimit - Splunk may not work due to small data segment limit!

Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...