Splunk Enterprise

DMP files generating in huge size

MsF-2000
Path Finder

Hi

In a particular server we are observing dmp files getting generated randomly and the size is too high like ~30 GB . and .log is generating with same name & location but cant relate the enteries in the crash .log

I checking the server utilization and found Splunkd process is consuming high both memory and CPU.

 

The server has 32 GB of RAM, 4 cores and UF version is 9.4.2 -Windows server machine - win 2022

0 Karma

MsF-2000
Path Finder

Thanks @livehybrid 

 

will check if not will raise a case for checking.

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @MsF-2000 

I dont think its a conincidence that the file size is similar to the amount of RAM...it sounds like something is memory leaking and then when it runs out of memory you're getting the 30GB dmp file. 

The first thing I would recommend is upgrading from 9.4.2 to 9.4.6 as this can help rule out any issues which have been fixed between those version and hopefully this will resolve the issue.

If it continues you may need to raise a Splunk support case for someone to dig deeper into the specifics of the issue on your server.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...