Splunk Search

std::bad_alloc

arrowecssupport
Communicator

I am running the search "index="os_var_log" | stats count" and getting this error after upgrading to Version 8 From version 6.5.5

Below is the job log, any ideas. This happens on any of my indexes big or small.

12-06-2019 12:31:38.706 ERROR SearchPhaseGenerator - Fallback to two phase search failed:std::bad_alloc
12-06-2019 12:31:38.707 ERROR SearchOrchestrator - std::bad_alloc
12-06-2019 12:31:38.707 ERROR SearchStatusEnforcer - sid:1575635498.9511 std::bad_alloc
12-06-2019 12:31:38.707 INFO  SearchStatusEnforcer - State changed to FAILED due to: std::bad_alloc
12-06-2019 12:31:38.707 INFO  SearchStatusEnforcer - Enforcing disk quota = 10485760000
12-06-2019 12:31:38.709 INFO  DispatchStorageManager - Remote storage disabled for search artifacts.
12-06-2019 12:31:38.709 INFO  DispatchManager - DispatchManager::dispatchHasFinished(id='1575635498.9511', username='admin')
12-06-2019 12:31:38.710 INFO  UserManager - Unwound user context: admin -> NULL
12-06-2019 12:31:38.710 INFO  UserManager - Unwound user context: admin -> NULL
12-06-2019 12:31:38.710 INFO  LookupProviderFactory - Clearing out lookup shared provider map
12-06-2019 12:31:38.712 ERROR dispatchRunner - RunDispatch::runDispatchThread threw error: std::bad_alloc
Tags (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...