Getting Data In

Splunk UF crashing frequently 6.3

rsathish47
Contributor

Hi All,

UF is crashing frequently . I didn't find any details in the splunkd logs

VERSION=6.3.0
BUILD=aa7d4b1ccb80
PRODUCT=splunk
PLATFORM=Linux-x86_64

Splunk Error Log:
splunkd: /home/build/build-src/ember/src/pipeline/input/Tailing.h:178: bool StatWrap::isDir() const: Assertion _valid' failed.
2016-09-19 07:10:30.089 +0200 splunkd started (build aa7d4b1ccb80)
splunkd: /home/build/build-src/ember/src/pipeline/input/Tailing.h:178: bool StatWrap::isDir() const: Assertion
_valid' failed.
2016-10-03 08:00:18.048 +0200 splunkd started (build aa7d4b1ccb80)
splunkd: /home/build/build-src/ember/src/pipeline/input/Tailing.h:178: bool StatWrap::isDir() const: Assertion `_valid' failed.
2016-10-17 19:22:31.964 +0200 splunkd started (build aa7d4b1ccb80)

Thanks
Sathish Rangan

Tags (1)
0 Karma

jwelch_splunk
Splunk Employee
Splunk Employee

http://docs.splunk.com/Documentation/Splunk/6.3.1/ReleaseNotes/6.3.1

2015-11-04 SPL-104078, SPL-104017 Splunkd crash due to assertion failure in Tailing.

This appears to be the same issue and is fixed in 6.3.1

I would suggest you upgrade.

dwaddle
SplunkTrust
SplunkTrust

When you hit an assertion or other crash condition, and you are running on something that is not the latest patch level for the release you are on - update first, then seek help from the community and/or support. There have been 8 public releases of Splunk 6.3 over the last year since Splunk 6.3.0 originally dropped.. Currently Splunk 6.3.8 is the latest, and the change logs (http://docs.splunk.com/Documentation/Splunk/6.3.8/ReleaseNotes/6.3.8) show it has dozens of fixes put in cumulatively to solve issues found.

The community is glad to help, but make sure you make the most of other people's time they contribute by attempting the easy fixes like upgrading first.

0 Karma
Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

Industry Solutions for Supply Chain and OT, Amazon Use Cases, Plus More New Articles ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...