Monitoring Splunk

Splunk server crush

sbarinov
Path Finder

We had our Splunk server stopping by itself two days in a row.

I am trying to find the reason but I cannot find anything related in /opt/splunk/var/log/splunk.

Could someone please advise where I should be looking for the related logs?

Labels (2)
0 Karma

sbarinov
Path Finder

As it was found, there was a kernel out of memory error.

We are running Version:7.2.5 on 12GB RAM.

I am wondering what we can do about that.

I will try to limit the amount of records in alert searches since we have them running all the time.

0 Karma
Get Updates on the Splunk Community!

Routing Data to Different Splunk Indexes in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

Getting Started with AIOps: Event Correlation Basics and Alert Storm Detection in ...

Getting Started with AIOps:Event Correlation Basics and Alert Storm Detection in Splunk IT Service ...

Register to Attend BSides SPL 2022 - It's all Happening October 18!

Join like-minded individuals for technical sessions on everything Splunk!  This is a community-led and run ...