Monitoring Splunk

Splunkd using all memory after upgrade from 5 to 6.1.1

jcrane
Explorer

Splunkd is taking almost 100% of memory after upgrading to 6.1.1. The box has become very sluggish and the web interface is basically unresponsive.

Looking for help in anyway.

Thanks

Update: I left it over night with no data being sent to it and it is doing the same thing still. I just don't know what to do with this now.
Does splunkd do some migration of the DB after an upgrade?

Tags (3)

rsolutions
Path Finder

Are you running Splunk on linux (RHEL)? How much memory do you have on the server? Have you looked at this:

http://docs.splunk.com/Documentation/Splunk/6.2.1/ReleaseNotes/SplunkandTHP

This may cause Splunk to under perform with THP enabled and even not release memory back to the server. The linux out of memory manager can also start to kill splunkd if it consumes too much memory.

http://www.oracle.com/technetwork/articles/servers-storage-dev/oom-killer-1911807.html

0 Karma

haliakbar_splun
Splunk Employee
Splunk Employee

Do you have Splunk_TA_Windows installed? If so check the version, if its old I would upgrade to 4.7.3

0 Karma

okrabbe_splunk
Splunk Employee
Splunk Employee

You should contact support. There is a lot that could be happening and they will need a diag.

http://www.splunk.com/support

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...