Getting Data In

Universal Forwarder Crash _initCrcLen' failed.

Kieffer87
Communicator

I have a universal forwarder running that picks up bluecoat logs from a directory. Everything works as expected, however every couple of hours the forwarder randomly crashes with the following error message in splunkd_stderr.log:

splunkd: /home/build/build-src/ivory/src/pipeline/input/ArchiveProcessor.cpp:1062: bool ArchiveCrcChecker::write(const char*, size_t): Assertion `_dataProv.curPos() < _initCrcLen' failed.

The files are compressed and contain headers which may be part of my issue but I'd like to know a bit more what this error message is referring to. The forwarder crashed almost constantly before I added the initCrcLength = 1000. I plan to try and increase this number to see if it helps but my headers only tend to be 400-500 bytes.

Inputs.conf
    [batch:///logs/proxy/splunkwatch/SG_*.log.gz]
    source = file.bluecoat
    sourcetype = bluecoat:proxysg:access:file
    disabled = false
    index = proxy
    move_policy = sinkhole
    initCrcLength = 1000

The files are unique with a date/time stamp so I thought about using crcSalt = however splunk doesn't seem to read the files at all using that.

Thoughts on what may be going on?

1 Solution

dwaddle
SplunkTrust
SplunkTrust

As a general rule, if you get an assertion that's a sign you need to submit a support case. To truly look into an assertion requires access to the source code, and few if any of us in the community have such rights.

View solution in original post

dwaddle
SplunkTrust
SplunkTrust

As a general rule, if you get an assertion that's a sign you need to submit a support case. To truly look into an assertion requires access to the source code, and few if any of us in the community have such rights.

ddrillic
Ultra Champion

Which version of the forwarder are you using? We had crashes saying StatWrap::isDir() const: Assertion_valid' failed` and by upgrading from 6.3.1 to 6.5, the problem got cleared.

0 Karma

Kieffer87
Communicator

Running a fresh install of 6.5.2

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...