Knowledge Management

Frequent KVstore crashes due to disk full error from mongod service while disk utilization is at 61%

myerasi
New Member

We have a six search-heads cluster and kv store is frequently crashing on one of them. The error we get is "KV Store process terminated abnormally (exit code 14, status exited with code 14). See mongod.log and splunkd.log for details". And when we look at the mongod.log, we had noticed the following disk full error: 2019-07-10T14:32:21.049Z I CONTROL [journal writer] LogFile::synchronousAppend failed with 8192 bytes unwritten out of 8192 bytes; b=0x55ebc4348000 errno:28 No space left on device
2019-07-10T14:32:21.050Z I - [journal writer] Fatal Assertion 13515

The disk utilization on the host is for the root partition / is at 61%. We did try cleaning up kvstore locally and resyncing it. The servers holds it for around 12 hours after every instance of cleanup and then kvstore crashes again.

Any help in this would be appreciable.

Thanks.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...