Splunk Enterprise Security

Host is frequently down in Linux. How to find the root cause

alexspunkshell
Contributor

Particular host if frequently down in linux. Kindly help me the steps to find the root cause and fix the issue.

0 Karma

codebuilder
Influencer

Most likely the ulimits are not set correctly and the splunk daemon is being killed off by the kernel. Verify ulimits are correct, and check network connectivity. If there is latency in the latter, the node may not be down but timing out in reporting health back to the cluster.

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...