Splunk Enterprise

after upgrade from splunk-7.3.1 to splunk-8.1.1 service crash

indeed_2000
Motivator

Hi

Upgrade from splunk-7.3.1 to splunk-8.1.1 have some issue:

 

1-when I going to "search page" at this url http://IP:9000/app/search/search

suddenly service stopped! I can't find any clue from logs. FYI when I going to other page service not fail and work correctly, but on search page stopped!

2-give this error (i try to change password as mention here but service still crash)

TailReader-0

  • Root Cause(s):
    • The monitor input cannot produce data because splunkd's processing queues are full. This will be caused by inadequate indexing or forwarding rate, or a sudden burst of incoming data.
  • Last 50 related messages:
    • 03-04-2021 21:23:44.451 +0330 WARN TailReader - Could not send data to output queue (parsingQueue), retrying...
    • 03-04-2021 21:23:38.011 +0330 INFO TailReader - State transitioning from 1 to 0 (initOrResume).
    • 03-04-2021 21:23:38.011 +0330 INFO TailReader - State transitioning from 1 to 0 (initOrResume).
    • 03-04-2021 21:23:38.007 +0330 INFO TailReader - batchreader0 waiting to be un-paused
    • 03-04-2021 21:23:38.007 +0330 INFO TailReader - Starting batchreader0 thread
    • 03-04-2021 21:23:38.007 +0330 INFO TailReader - Registering metrics callback for: batchreader0
    • 03-04-2021 21:23:38.005 +0330 INFO TailReader - tailreader0 waiting to be un-paused
    • 03-04-2021 21:23:38.005 +0330 INFO TailReader - Starting tailreader0 thread
    • 03-04-2021 21:23:38.004 +0330 INFO TailReader - Registering metrics callback for: tailreader0

 

Any idea?

Thanks,

Tags (3)
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...