Monitoring Splunk

when splunk crash,how can i got the information

perlish
Communicator

Sometimes, i found splunk will crash.
I want to konw why it crash, how can i got the log?

Tags (1)
0 Karma

Drainy
Champion

If you install the Splunk on Splunk app it provides a helpful shortcut and dashboard to view crash logs which you can then send onto support with a diag if it doesn't appear to be anything preventable or caused by any local factors 🙂

http://splunk-base.splunk.com/apps/29008/sos-splunk-on-splunk

DaveSavage
Builder

Which operating system Perlish? For Linux I believe the files go in $SPLUNK_HOME$\var\log\splunk

kristian_kolb
Ultra Champion

The crash logs would be called 'crash-yyyy-mm-dd-HH:MM:SS.log'.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...