Monitoring Splunk

Splunk Indexer server crashes and keep going down

Zarack
Engager

Hello, I have a server indexer that crashes from time to time, what is the best way to investigate what caused the problem?

How can I see the logs through index=_internal and splunkd.log?

Tags (1)
0 Karma

SonOfBuzi
Loves-to-Learn Lots

 there is crash logs on the server in $SPLUNK_HOME/var/log/splunk/crash*.log it gets ingested under sourcetype=splunkd_crash_log

0 Karma
Get Updates on the Splunk Community!

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

Cisco Use Cases, ITSI Best Practices, and More New Articles from Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...