Splunk SOAR

Phantom 4.1 startup error

karthikes
New Member

Dear Team,

I am karthik from prudential singapore, our Phantom UAT server suddenly goes down.

when we attempt to restart the server it says pgbouncer failed, server reboot didn't help.

i have pasted the error messages below, Could you please check and let me know how to resolve this error.

 

[frioux03@asgprholupht001 ~]$ dzdo /apps/phantom/bin/stop_daemon.sh all
phantom_decided is already stopped
phantom_workflowd is already stopped
phantom_ingestd is already stopped
phantom_actiond is already stopped
phantom_clusterd is already stopped
[frioux03@asgprholupht001 ~]$ dzdo /apps/phantom/bin/stop_phantom.sh
Shutting down all Phantom services
Phantom shutdown successful
[frioux03@asgprholupht001 ~]$ dzdo /apps/phantom/bin/start_phantom.sh
Starting all Phantom services
Phantom startup failed: pgbouncer
[frioux03@asgprholupht001 ~]$
 
[342122@asgprholupht001 ~]$ systemctl status pgbouncer.service
● pgbouncer.service - A lightweight connection pooler for PostgreSQL
Loaded: loaded (/etc/systemd/system/pgbouncer.service; enabled; vendor preset: disabled)
Active: failed (Result: exit-code) since Wed 2020-07-08 10:55:52 UTC; 16min ago
Process: 4870 ExecStop=/opt/phantom/bin/stop_pgbouncer.sh $MAINPID (code=exited, status=203/EXEC)
Process: 4343 ExecReload=/usr/bin/kill -HUP $MAINPID (code=exited, status=0/SUCCESS)
Process: 4704 ExecStart=/usr/bin/pgbouncer -d -q ${BOUNCERCONF} (code=exited, status=0/SUCCESS)
Main PID: 4706 (code=exited, status=0/SUCCESS)
 
thanks
karthik
Labels (3)
0 Karma

sam_splunk
Splunk Employee
Splunk Employee

Any update on your situation?

0 Karma

phanTom
SplunkTrust
SplunkTrust

@karthikes no sure if you ever worked out what was wrong but I take it you checked space for the database is not restricted/full?

The pgbouncer account is used to access the database so if this is a single system (non-clusered) there must be an issue communicating or starting the database up.

If this helped , please tick below! Thanks.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...