Splunk Enterprise

Search Head getting crashed

anandhalagarasa
Path Finder

Our Primary search head got crashed twice today. When cross verified we found out this is the error message in Crash.log so how should we need to fix it asap.

Error Message:
Received fatal signal 6 (Aborted).
Cause:
Signal sent by PID xxx36 running under UID 99xx.
Crashing thread: IdataDO_Collector

Tags (1)
0 Karma

sudosplunk
Motivator

Hi there,
Just making sure, did you check the following conditions,

Having enough disk space - For linux,du -sh $SPLUNK_HOME/
Any user running expensive searches - If you've configured Monitoring console, you can navigate to search -> Activity -> Search Activity: Instance OR go to Jobs Manager page.

0 Karma

jkat54
SplunkTrust
SplunkTrust

See if this helps:
https://answers.splunk.com/answers/330827/after-upgrade-from-62-to-63-unable-to-start-splunk.html

vranjith009 · Dec 07, 2015 at 10:25 PM
Thanks mfrost8 for your reply.

Error was due to some permission issue of audit db files and "indexes.conf" . Given splunk:splunk permission to all audit db buckets and tracing of bad index conf file by using "./splunk cmd btool indexes list --debug|more" help us for closing the issue.
0 Karma

deepashri_123
Motivator

Hey@anandhalagarasan,

What version of splunk are you using?

0 Karma

anandhalagarasa
Path Finder

Splunk 6.5.0 (build 59c8927def0f)

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...