Splunk Enterprise

Splunk Enterprise instance is shutting down due to signal 15

akk_coder
Loves-to-Learn Lots

It occurs 3-4 hours after starting splunk. 

These are the logs found in splunk/var/log/splunk/mongod.log

I CONTROL [signalProcessingThread] got signal 15 (Terminated), will terminate after current cmd ends

I NETWORK [signalProcessingThread] shutdown: going to close listening sockets...

I REPL [signalProcessingThread] shutting down replication subsystems

I REPL [signalProcessingThread] Stopping replication reporter thread

I REPL [signalProcessingThread] Stopping replication fetcher thread

I REPL [signalProcessingThread] Stopping replication applier thread

 

 

Labels (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

could you found anything interesting from spulunkd.log or /var/log/messages or "dmesg -T" ?

Could there be an OoM (out of memory) situation? This should be seen on messages or with dmesg command.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf24, and Community Connections

Thank you to everyone in the Splunk Community who joined us for .conf24 – starting with Splunk University and ...

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...