Installation

Splunk-optimize Crashes All the time

aelliott
Motivator

Since installing Enterprise Security, Splunk-optimize crashes all the time on my machine.
I've tested this on another machine as well.
We are using splunk 6.0.3

Log Name:      Application
Source:        Application Error
Date:          5/9/2014 1:33:55 PM
Event ID:      1000
Task Category: (100)
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      myIndexer.myCompany.com
Description:
Faulting application name: splunk-optimize.exe, version: 1536.768.0.7498, time stamp: 0x5344d6ef
Faulting module name: MSVCR110.dll, version: 11.0.51106.1, time stamp: 0x5098826e
Exception code: 0xc0000417
Fault offset: 0x000000000006d4f9
Faulting process id: 0xcfc
Faulting application start time: 0x01cf6bb53be10712
Faulting application path: D:\Program Files\Splunk\bin\splunk-optimize.exe
Faulting module path: D:\Program Files\Splunk\bin\MSVCR110.dll
Report Id: 79aee57d-d7a8-11e3-9663-001ec92d4e67
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Application Error" />
    <EventID Qualifiers="0">1000</EventID>
    <Level>2</Level>
    <Task>100</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2014-05-09T18:33:55.000000000Z" />
    <EventRecordID>6403</EventRecordID>
    <Channel>Application</Channel>
    <Computer>myindexer.mycompany.com</Computer>
    <Security />
  </System>
  <EventData>
    <Data>splunk-optimize.exe</Data>
    <Data>1536.768.0.7498</Data>
    <Data>5344d6ef</Data>
    <Data>MSVCR110.dll</Data>
    <Data>11.0.51106.1</Data>
    <Data>5098826e</Data>
    <Data>c0000417</Data>
    <Data>000000000006d4f9</Data>
    <Data>cfc</Data>
    <Data>01cf6bb53be10712</Data>
    <Data>D:\Program Files\Splunk\bin\splunk-optimize.exe</Data>
    <Data>D:\Program Files\Splunk\bin\MSVCR110.dll</Data>
  </EventData>
</Event>
Tags (1)

ogerami
New Member

I had a similar error on startup. I looked in the splunk logs - %ProgramFiles%\SplunkUniversalForwarder\var\log\splunk\splunkd.log and it turned out to be a completely different issue. It had to do with corrupt permissions on the forwarder input.config files. Just as a pointer to maybe start from the log files and go from there.

Hope this helps someone.

0 Karma

aminurr
New Member

we are getting same error on 6.3.3 Enterprise Splunk

0 Karma

vidyadharms
New Member

We are also getting similaer error on 6.4.2

Faulting application name: splunkd.exe, version: 1540.512.22387.7973, time stamp: 0x57732383
Faulting module name: splunkd.exe, version: 1540.512.22387.7973, time stamp: 0x57732383
Exception code: 0xc0000409
Fault offset: 0x00000000013d95a4
Faulting process id: 0xdbc
Faulting application start time: 0x01d2081f7b1c9af5
Faulting application path: D:\Splunk\bin\splunkd.exe
Faulting module path: D:\Splunk\bin\splunkd.exe
Report Id: 6f07e8c0-741b-11e6-810d-005056875d90
Faulting package full name:
Faulting package-relative application ID:

Does anyone has any fix to it?

0 Karma

letienne
Path Finder

I did not notice it until now, but we have the same issue on our side with 6.2.4.

Tried reinstalling the vcredist package without luck.

Did anyone find a way to fix this?

Or have an idea of the impact?

Thanks!

0 Karma

Anthony233
New Member

It seems that there is something wrong with msvcr110.dll module. Since msvcr110.dll is part of Visual C++ Redistributable for Visual Studio 2012 Update 4, when encounter the missing error, you can download and install the VC++ redistributable packages to fix the problem.
Click on the links below to download the package you need:

(http://www.microsoft.com/en-us/download/details.aspx?id=30679# )

source: http://www.bestpcsavior.com/how-to-effectively-fix-msvcr110-dll-missing-error/
Good luck.

0 Karma

rsolutions
Path Finder

The splunk-optimize process is using way too much memory in our environment (with ES installed) and is crashing the indexers... were you able to resolve your issue and if so... how?

0 Karma

rroca
New Member

Getting same error on Windows 2008 R2 with Splunk 6.1.3 any updates

0 Karma

wyodoc1
Explorer

Any updates?

0 Karma

aelliott
Motivator

Per Splunk on my case: The fix will be included in 6.0.6 (and 6.1.2).

0 Karma

bosburn_splunk
Splunk Employee
Splunk Employee

This has been identified as a bug in SPL-84446 and will be fixed in an upcoming version.

Brian

laristote
Explorer

I have the same problem. Did you find somtething?
I'm using Splunk 6.1.1 with ES 3.0.1

0 Karma

aelliott
Motivator

I have a ticket in with splunk support on this issue.

0 Karma
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...