Installation

How to prevent Splunk on MacOS from "freezing"

yuanliu
SplunkTrust
SplunkTrust

For years I have kept a standalone Splunk Enterprise running on Macbooks.  Typically I keep MacOS in sleep or running mode overnight.  Splunk will run until I reboot (or forced restart).  Never had a problem.

But in the past two weeks, I had two nights during which splunkd on one Macbook entered a "frozen" state in that it will respond to some HTTP queries (e.g., listing dashboards) but all search jobs stopped responding.  I had to either run the Splunk launcher to stop it then relaunch, or reboot.

Meanwhile, another Macbook continues to run Splunk fine (in sleep mode).

Anyone experience the same?  What could be possible causes?  Neither instance has any recurring jobs or ingestion.  Current version is 9.1.2.  The problematic one runs MacOS 12.7.3/M1. (Last updated some weeks ago.)  The other one runs the same MacOS on Intel.

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

I suppose that you have already try next steps?

  • Ingest macOS internal logs to splunk (preferred another instance)
  • check are there anything on macOS console app?

I have been running already years splunkd on macOS till 13.6.4 mainly in intel. I have also one instance on M1, but I haven't seen this kind of behaviour.

r. Ismo

0 Karma

yuanliu
SplunkTrust
SplunkTrust

Thanks for the tip.  I'm afraid I don't quite know what to ingest on Mac or how to do it right especially if it should be shipped to another instance.  The problematic one is a work computer that is connected to corporate VPN (but will disconnect from time to time) and runs a bunch of corporate "security stuff" like MS Defender.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...