Monitoring Splunk

Splunk server crush

sbarinov
Path Finder

We had our Splunk server stopping by itself two days in a row.

I am trying to find the reason but I cannot find anything related in /opt/splunk/var/log/splunk.

Could someone please advise where I should be looking for the related logs?

Labels (2)
0 Karma

sbarinov
Path Finder

As it was found, there was a kernel out of memory error.

We are running Version:7.2.5 on 12GB RAM.

I am wondering what we can do about that.

I will try to limit the amount of records in alert searches since we have them running all the time.

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...