Monitoring Splunk

Splunk issue - bad allocation error

uagraw01
Motivator

Hello Splunkers!!

I am getting "Bad allocation" error on all the Splunk dashboard panel. Please help me to identify the potential root cause.

uagraw01_0-1728641318047.png

 

Labels (1)
Tags (1)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @uagraw01 Looks like this issue is about memory. Could you pls check memory usage on this Splunk instance, thanks. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

uagraw01
Motivator

@inventsekar I have updated the limits.conf under system/local and it does not impact anything. Issue is still  persist.

[default]
max_mem_usage_mb = 500

[searchresults]
maxresultrows = 86400
0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...