Splunk Enterprise

after upgrade from splunk-7.3.1 to splunk-8.1.1 service crash

indeed_2000
Motivator

Hi

Upgrade from splunk-7.3.1 to splunk-8.1.1 have some issue:

 

1-when I going to "search page" at this url http://IP:9000/app/search/search

suddenly service stopped! I can't find any clue from logs. FYI when I going to other page service not fail and work correctly, but on search page stopped!

2-give this error (i try to change password as mention here but service still crash)

TailReader-0

  • Root Cause(s):
    • The monitor input cannot produce data because splunkd's processing queues are full. This will be caused by inadequate indexing or forwarding rate, or a sudden burst of incoming data.
  • Last 50 related messages:
    • 03-04-2021 21:23:44.451 +0330 WARN TailReader - Could not send data to output queue (parsingQueue), retrying...
    • 03-04-2021 21:23:38.011 +0330 INFO TailReader - State transitioning from 1 to 0 (initOrResume).
    • 03-04-2021 21:23:38.011 +0330 INFO TailReader - State transitioning from 1 to 0 (initOrResume).
    • 03-04-2021 21:23:38.007 +0330 INFO TailReader - batchreader0 waiting to be un-paused
    • 03-04-2021 21:23:38.007 +0330 INFO TailReader - Starting batchreader0 thread
    • 03-04-2021 21:23:38.007 +0330 INFO TailReader - Registering metrics callback for: batchreader0
    • 03-04-2021 21:23:38.005 +0330 INFO TailReader - tailreader0 waiting to be un-paused
    • 03-04-2021 21:23:38.005 +0330 INFO TailReader - Starting tailreader0 thread
    • 03-04-2021 21:23:38.004 +0330 INFO TailReader - Registering metrics callback for: tailreader0

 

Any idea?

Thanks,

Tags (3)
0 Karma
Get Updates on the Splunk Community!

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

New Learning Videos on Topics Most Requested by You! Plus This Month’s New Splunk ...

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

How I Instrumented a Rust Application Without Knowing Rust

As a technical writer, I often have to edit or create code snippets for Splunk's distributions of ...