Whenever do a particular search, Splunk always crashes with error
"/opt/splunk/p4/splunk/branches/prince/src/search/processors/SortProcessor.cpp:297: bool rescomp_t::operator<(rescomp_t) const: Assertion `first.size() == other.first.size()' failed." in crash files.
Search query:
host="m1pm*" OR host=m1crim* OR host=m1ph* OR host=m1prim* source="WMI:FreeDiskSpace"
| stats first(FreeMegabytes) as free last(FreeMegabytes) as oldfree by host Name
| eval "%Change from 24 hours ago (GB)" = tostring((((free - oldfree)/1024/oldfree)*100), "commas")
| fields - oldfree | eval free=tostring(free/1024) | eval free=tostring(free, "commas")
| rename free as "Free (GB)"
We should get the matching crashlog (and on windows DMP) files and get a bug opened. If you're hoping for a guess, you could ask Dr Z if he has any idea.
Looks to me like a plain bug, but it might be helpful to know:
Does the plain search
host="m1pm*" OR host=m1crim* OR host=m1ph* OR host=m1prim* source="WMI:FreeDiskSpace"
(without any stats
or other commands`) crash?
If not, does
host="m1pm*" OR host=m1crim* OR host=m1ph* OR host=m1prim* source="WMI:FreeDiskSpace"
| stats count by host Name
(all one search, I split lines for readability) crash?
If not, what's the output of
host="m1pm*" OR host=m1crim* OR host=m1ph* OR host=m1prim* source="WMI:FreeDiskSpace"
| stats count by host Name | stats count by host
and
host="m1pm*" OR host=m1crim* OR host=m1ph* OR host=m1prim* source="WMI:FreeDiskSpace"
| stats count by host Name | stats count by Name
if they don't crash?