Getting Data In

Why does Splunkd crash after start service for a few minutes.


I'm running splunk version 4.0.7 on Windows Server 2008 SP2 x86-64. It's work fine for a couple months. After environmental power failure last weekend. Splunk crash after start service for a minute. Crash log says:

[build 72459]
 C++ exception: object@[0x0000000002ECDBA8], type@[0x0000000140F63708]
 Exception is Non-continuable
 Exception address: [0x0000000076F576FD]
 Crashing thread: indexerPipe
    MxCsr:  [0x0000000000001F80]
    SegDs:  [0x000000000000002B]
    SegEs:  [0x000000000000002B]
    SegFs:  [0x0000000000000053]
    SegGs:  [0x000000000000002B]
    SegSs:  [0x000000000000002B]
    SegCs:  [0x0000000000000033]
    EFlags:  [0x0000000000000206]
    Rsp:  [0x0000000002ECDA10]
    Rip:  [0x0000000076F576FD] RaiseException + 61/80
    Dr0:  [0x00000000002D8724]
    Dr1:  [0x0000000000000000]
    Dr2:  [0x00000000002DA190]
    Dr3:  [0x0000000000920090]
    Dr6:  [0x00000000013187F0]
    Dr7:  [0x0000000001F252A5]
    Rax:  [0x0000000002ECDA50]
    Rcx:  [0x0000000002ECD520]
    Rdx:  [0x00000000000000D0]
    Rbx:  [0x0000000140F63708]
    Rbp:  [0x0000000002ECDD60]
    Rsi:  [0x0000000002ECDCA0]
    Rdi:  [0x000000000453AB70]
    R8:  [0x0000000000000000]
    R9:  [0x0000000000000000]
    R10:  [0x0000000140000000]
    R11:  [0x0000000002ECDA50]
    R12:  [0x0000000000000000]
    R13:  [0x0000000002ECE328]
    R14:  [0x000000000437AC10]
    R15:  [0x0000000003C6C2A0]
    DebugControl:  [0x000000000437AC10]
    LastBranchToRip:  [0x0000000002ECE328]
    LastBranchFromRip:  [0xFFFFFFFFFFFFFFFF]
    LastExceptionToRip:  [0x000000000000001F]
    LastExceptionFromRip:  [0x0000000071346E97]

 OS: Windows
 Arch: x86-64

    Frame  0 @[0x0000000002ECDD60]:  [0x000001AAC9191ACA] ?
    Frame  1 @[0x0000000000000000]: (Frame below stack)

 Crash dump written to: D:\Program Files\Splunk\var\log\splunk\D__Program Files_Splunk_bin_splunkd_exe_crash-2010-06-25-14-57-51.dmp

TBMALOG /6.0 Service Pack 2
Tags (3)


Most likely you have some corrupted metadata files that are preventing Splunk from starting. You can try to repair them yourself. Refer to the following answers topic:

Get Updates on the Splunk Community!

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...