Installation

Splunk-optimize Crashes All the time

aelliott
Motivator

Since installing Enterprise Security, Splunk-optimize crashes all the time on my machine.
I've tested this on another machine as well.
We are using splunk 6.0.3

Log Name:      Application
Source:        Application Error
Date:          5/9/2014 1:33:55 PM
Event ID:      1000
Task Category: (100)
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      myIndexer.myCompany.com
Description:
Faulting application name: splunk-optimize.exe, version: 1536.768.0.7498, time stamp: 0x5344d6ef
Faulting module name: MSVCR110.dll, version: 11.0.51106.1, time stamp: 0x5098826e
Exception code: 0xc0000417
Fault offset: 0x000000000006d4f9
Faulting process id: 0xcfc
Faulting application start time: 0x01cf6bb53be10712
Faulting application path: D:\Program Files\Splunk\bin\splunk-optimize.exe
Faulting module path: D:\Program Files\Splunk\bin\MSVCR110.dll
Report Id: 79aee57d-d7a8-11e3-9663-001ec92d4e67
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Application Error" />
    <EventID Qualifiers="0">1000</EventID>
    <Level>2</Level>
    <Task>100</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2014-05-09T18:33:55.000000000Z" />
    <EventRecordID>6403</EventRecordID>
    <Channel>Application</Channel>
    <Computer>myindexer.mycompany.com</Computer>
    <Security />
  </System>
  <EventData>
    <Data>splunk-optimize.exe</Data>
    <Data>1536.768.0.7498</Data>
    <Data>5344d6ef</Data>
    <Data>MSVCR110.dll</Data>
    <Data>11.0.51106.1</Data>
    <Data>5098826e</Data>
    <Data>c0000417</Data>
    <Data>000000000006d4f9</Data>
    <Data>cfc</Data>
    <Data>01cf6bb53be10712</Data>
    <Data>D:\Program Files\Splunk\bin\splunk-optimize.exe</Data>
    <Data>D:\Program Files\Splunk\bin\MSVCR110.dll</Data>
  </EventData>
</Event>
Tags (1)

ogerami
New Member

I had a similar error on startup. I looked in the splunk logs - %ProgramFiles%\SplunkUniversalForwarder\var\log\splunk\splunkd.log and it turned out to be a completely different issue. It had to do with corrupt permissions on the forwarder input.config files. Just as a pointer to maybe start from the log files and go from there.

Hope this helps someone.

0 Karma

aminurr
New Member

we are getting same error on 6.3.3 Enterprise Splunk

0 Karma

vidyadharms
New Member

We are also getting similaer error on 6.4.2

Faulting application name: splunkd.exe, version: 1540.512.22387.7973, time stamp: 0x57732383
Faulting module name: splunkd.exe, version: 1540.512.22387.7973, time stamp: 0x57732383
Exception code: 0xc0000409
Fault offset: 0x00000000013d95a4
Faulting process id: 0xdbc
Faulting application start time: 0x01d2081f7b1c9af5
Faulting application path: D:\Splunk\bin\splunkd.exe
Faulting module path: D:\Splunk\bin\splunkd.exe
Report Id: 6f07e8c0-741b-11e6-810d-005056875d90
Faulting package full name:
Faulting package-relative application ID:

Does anyone has any fix to it?

0 Karma

letienne
Path Finder

I did not notice it until now, but we have the same issue on our side with 6.2.4.

Tried reinstalling the vcredist package without luck.

Did anyone find a way to fix this?

Or have an idea of the impact?

Thanks!

0 Karma

Anthony233
New Member

It seems that there is something wrong with msvcr110.dll module. Since msvcr110.dll is part of Visual C++ Redistributable for Visual Studio 2012 Update 4, when encounter the missing error, you can download and install the VC++ redistributable packages to fix the problem.
Click on the links below to download the package you need:

(http://www.microsoft.com/en-us/download/details.aspx?id=30679# )

source: http://www.bestpcsavior.com/how-to-effectively-fix-msvcr110-dll-missing-error/
Good luck.

0 Karma

rsolutions
Path Finder

The splunk-optimize process is using way too much memory in our environment (with ES installed) and is crashing the indexers... were you able to resolve your issue and if so... how?

0 Karma

rroca
New Member

Getting same error on Windows 2008 R2 with Splunk 6.1.3 any updates

0 Karma

wyodoc1
Explorer

Any updates?

0 Karma

aelliott
Motivator

Per Splunk on my case: The fix will be included in 6.0.6 (and 6.1.2).

0 Karma

bosburn_splunk
Splunk Employee
Splunk Employee

This has been identified as a bug in SPL-84446 and will be fixed in an upcoming version.

Brian

laristote
Explorer

I have the same problem. Did you find somtething?
I'm using Splunk 6.1.1 with ES 3.0.1

0 Karma

aelliott
Motivator

I have a ticket in with splunk support on this issue.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...