Splunk Enterprise

Universal forwarder version 10 memory leak

Ixionz
New Member

I am currently in the testing phase of getting our universal forwarders to a more standardized version (either 9.4.4 or version 10), however when I roll out the new version to any VM's splunkforwarder chews up over 80% of memory which causes overall memory utilization to be around 100%  constantly which I am forced to rollback to version 9.4.4

Nothing has been changed at all except the version. 

 

Is anyone else experiencing similar behavior when they upgrade to version 10 or even do a new install, or has anyone else seen this behavior out there (not necessarily VM's but maybe physical boxes) as i don't want to roll something out to our environment and causes more problems than solutions.

 

 

0 Karma

darren
New Member

I was told to try the fix in:

https://community.splunk.com/t5/Splunk-Enterprise/URGENT-All-splunk-forwarders-upgraded-to-10-0-vers...

"Disabled the

evt_resolve_ad_obj = 0 

in Splunk_TA_windows app , logs have now ceased. "

 

For reference, this is the ticket I made.  Luckily, we were able to catch this issue in dev before deploying 10.0.0.0 to prod.

https://community.splunk.com/t5/Splunk-Enterprise/In-UniversalForwarder-10-0-0-0-splunk-winevtlog-ex...

0 Karma

darren
New Member

However, if we do the below "fix", then AD SID and AD GUID strings won't be resolved to the actual AD names, which would be really annoying.  I think we're going to hold off on 10.0.0.0 until the evt_resolve_ad_obj feature is fixed and working again without crashing our servers.

 

[WinEventLog://Security] stanzas inside of inputs.conf:

evt_resolve_ad_obj = 0

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Please create a support ticket.

Anyhow it's best practice to wait something like X.0.3 or even X.1.2 or similar before go into production. There have been almost every time when a new version has launched more or less nasty and critical bugs.

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Ixionz 

Are you able to confirm please the name of the process(es) running which consume this amount of memory? And also the total amount of memory on these VMs?

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...