Monitoring Splunk

Why do we get kernel:BUG: soft lockup on the Search Head?

ddrillic
Ultra Champion

We get the following -

$ ./splunk status

Message from syslogd@<host> at Oct 11 06:02:24 ...
kernel:BUG: soft lockup - CPU#0 stuck for 90s! [setroubleshootd:6739]

Message from syslogd@<host>  at Oct 11 06:05:27 ...
kernel:BUG: soft lockup - CPU#0 stuck for 66s! [perfd:63790]

Message from syslogd@<host>  at Oct 11 06:05:27 ...
kernel:BUG: soft lockup - CPU#3 stuck for 68s! [kblockd/3:157]

Message from syslogd@<host>  at Oct 11 06:05:28 ...
kernel:BUG: soft lockup - CPU#8 stuck for 66s! [splunkd:2903]
Tags (2)
0 Karma
1 Solution

inventsekar
SplunkTrust
SplunkTrust

which linux version you are running..

googled for the kernel bug and found this -
https://access.redhat.com/solutions/2039183
it suggest the resolution as:
Update to the RHEL 6.7 kernel package (kernel-2.6.32-573.el6) or later

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !

View solution in original post

0 Karma

harsmarvania57
Ultra Champion

Few questions

  1. Are you running splunk on NFS ?
  2. Are your splunk running on VMWare or Physical host?
0 Karma

inventsekar
SplunkTrust
SplunkTrust

which linux version you are running..

googled for the kernel bug and found this -
https://access.redhat.com/solutions/2039183
it suggest the resolution as:
Update to the RHEL 6.7 kernel package (kernel-2.6.32-573.el6) or later

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

ddrillic
Ultra Champion

I see -

$ uname -a
Linux <host> 2.6.32-642.1.1.el6.x86_64 #1 SMP Fri May 6 14:54:05 EDT 2016 x86_64 x86_64 x86_64 GNU/Linux

So, we are at 2.6.32-642.1.1.el6.

0 Karma
Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...