Getting Data In

Splunk UF crashing frequently 6.3

rsathish47
Contributor

Hi All,

UF is crashing frequently . I didn't find any details in the splunkd logs

VERSION=6.3.0
BUILD=aa7d4b1ccb80
PRODUCT=splunk
PLATFORM=Linux-x86_64

Splunk Error Log:
splunkd: /home/build/build-src/ember/src/pipeline/input/Tailing.h:178: bool StatWrap::isDir() const: Assertion _valid' failed.
2016-09-19 07:10:30.089 +0200 splunkd started (build aa7d4b1ccb80)
splunkd: /home/build/build-src/ember/src/pipeline/input/Tailing.h:178: bool StatWrap::isDir() const: Assertion
_valid' failed.
2016-10-03 08:00:18.048 +0200 splunkd started (build aa7d4b1ccb80)
splunkd: /home/build/build-src/ember/src/pipeline/input/Tailing.h:178: bool StatWrap::isDir() const: Assertion `_valid' failed.
2016-10-17 19:22:31.964 +0200 splunkd started (build aa7d4b1ccb80)

Thanks
Sathish Rangan

Tags (1)
0 Karma

jwelch_splunk
Splunk Employee
Splunk Employee

http://docs.splunk.com/Documentation/Splunk/6.3.1/ReleaseNotes/6.3.1

2015-11-04 SPL-104078, SPL-104017 Splunkd crash due to assertion failure in Tailing.

This appears to be the same issue and is fixed in 6.3.1

I would suggest you upgrade.

dwaddle
SplunkTrust
SplunkTrust

When you hit an assertion or other crash condition, and you are running on something that is not the latest patch level for the release you are on - update first, then seek help from the community and/or support. There have been 8 public releases of Splunk 6.3 over the last year since Splunk 6.3.0 originally dropped.. Currently Splunk 6.3.8 is the latest, and the change logs (http://docs.splunk.com/Documentation/Splunk/6.3.8/ReleaseNotes/6.3.8) show it has dozens of fixes put in cumulatively to solve issues found.

The community is glad to help, but make sure you make the most of other people's time they contribute by attempting the easy fixes like upgrading first.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...