Splunk-optimize Crashes All the time


Since installing Enterprise Security, Splunk-optimize crashes all the time on my machine.
I've tested this on another machine as well.
We are using splunk 6.0.3

Log Name:      Application
Source:        Application Error
Date:          5/9/2014 1:33:55 PM
Event ID:      1000
Task Category: (100)
Level:         Error
Keywords:      Classic
User:          N/A
Faulting application name: splunk-optimize.exe, version: 1536.768.0.7498, time stamp: 0x5344d6ef
Faulting module name: MSVCR110.dll, version: 11.0.51106.1, time stamp: 0x5098826e
Exception code: 0xc0000417
Fault offset: 0x000000000006d4f9
Faulting process id: 0xcfc
Faulting application start time: 0x01cf6bb53be10712
Faulting application path: D:\Program Files\Splunk\bin\splunk-optimize.exe
Faulting module path: D:\Program Files\Splunk\bin\MSVCR110.dll
Report Id: 79aee57d-d7a8-11e3-9663-001ec92d4e67
Event Xml:
<Event xmlns="">
    <Provider Name="Application Error" />
    <EventID Qualifiers="0">1000</EventID>
    <TimeCreated SystemTime="2014-05-09T18:33:55.000000000Z" />
    <Security />
    <Data>D:\Program Files\Splunk\bin\splunk-optimize.exe</Data>
    <Data>D:\Program Files\Splunk\bin\MSVCR110.dll</Data>
Tags (1)

New Member

I had a similar error on startup. I looked in the splunk logs - %ProgramFiles%\SplunkUniversalForwarder\var\log\splunk\splunkd.log and it turned out to be a completely different issue. It had to do with corrupt permissions on the forwarder input.config files. Just as a pointer to maybe start from the log files and go from there.

Hope this helps someone.

0 Karma

New Member

we are getting same error on 6.3.3 Enterprise Splunk

0 Karma

New Member

We are also getting similaer error on 6.4.2

Faulting application name: splunkd.exe, version: 1540.512.22387.7973, time stamp: 0x57732383
Faulting module name: splunkd.exe, version: 1540.512.22387.7973, time stamp: 0x57732383
Exception code: 0xc0000409
Fault offset: 0x00000000013d95a4
Faulting process id: 0xdbc
Faulting application start time: 0x01d2081f7b1c9af5
Faulting application path: D:\Splunk\bin\splunkd.exe
Faulting module path: D:\Splunk\bin\splunkd.exe
Report Id: 6f07e8c0-741b-11e6-810d-005056875d90
Faulting package full name:
Faulting package-relative application ID:

Does anyone has any fix to it?

0 Karma

Path Finder

I did not notice it until now, but we have the same issue on our side with 6.2.4.

Tried reinstalling the vcredist package without luck.

Did anyone find a way to fix this?

Or have an idea of the impact?


0 Karma

New Member

It seems that there is something wrong with msvcr110.dll module. Since msvcr110.dll is part of Visual C++ Redistributable for Visual Studio 2012 Update 4, when encounter the missing error, you can download and install the VC++ redistributable packages to fix the problem.
Click on the links below to download the package you need:

( )

Good luck.

0 Karma

Path Finder

The splunk-optimize process is using way too much memory in our environment (with ES installed) and is crashing the indexers... were you able to resolve your issue and if so... how?

0 Karma

New Member

Getting same error on Windows 2008 R2 with Splunk 6.1.3 any updates

0 Karma


Any updates?

0 Karma


Per Splunk on my case: The fix will be included in 6.0.6 (and 6.1.2).

0 Karma

Splunk Employee
Splunk Employee

This has been identified as a bug in SPL-84446 and will be fixed in an upcoming version.



I have the same problem. Did you find somtething?
I'm using Splunk 6.1.1 with ES 3.0.1

0 Karma


I have a ticket in with splunk support on this issue.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Using the Splunk Threat Research Team’s Latest Security Content

REGISTER HERE Tech Talk | Security Edition Did you know the Splunk Threat Research Team regularly releases ...

SplunkTrust | 2024 SplunkTrust Application Period is Open!

It's that time again, folks! That's right, the application/nomination period for the 2024 SplunkTrust is ...