Getting Data In

Splunk UF crashing frequently 6.3

rsathish47
Contributor

Hi All,

UF is crashing frequently . I didn't find any details in the splunkd logs

VERSION=6.3.0
BUILD=aa7d4b1ccb80
PRODUCT=splunk
PLATFORM=Linux-x86_64

Splunk Error Log:
splunkd: /home/build/build-src/ember/src/pipeline/input/Tailing.h:178: bool StatWrap::isDir() const: Assertion _valid' failed.
2016-09-19 07:10:30.089 +0200 splunkd started (build aa7d4b1ccb80)
splunkd: /home/build/build-src/ember/src/pipeline/input/Tailing.h:178: bool StatWrap::isDir() const: Assertion
_valid' failed.
2016-10-03 08:00:18.048 +0200 splunkd started (build aa7d4b1ccb80)
splunkd: /home/build/build-src/ember/src/pipeline/input/Tailing.h:178: bool StatWrap::isDir() const: Assertion `_valid' failed.
2016-10-17 19:22:31.964 +0200 splunkd started (build aa7d4b1ccb80)

Thanks
Sathish Rangan

Tags (1)
0 Karma

jwelch_splunk
Splunk Employee
Splunk Employee

http://docs.splunk.com/Documentation/Splunk/6.3.1/ReleaseNotes/6.3.1

2015-11-04 SPL-104078, SPL-104017 Splunkd crash due to assertion failure in Tailing.

This appears to be the same issue and is fixed in 6.3.1

I would suggest you upgrade.

dwaddle
SplunkTrust
SplunkTrust

When you hit an assertion or other crash condition, and you are running on something that is not the latest patch level for the release you are on - update first, then seek help from the community and/or support. There have been 8 public releases of Splunk 6.3 over the last year since Splunk 6.3.0 originally dropped.. Currently Splunk 6.3.8 is the latest, and the change logs (http://docs.splunk.com/Documentation/Splunk/6.3.8/ReleaseNotes/6.3.8) show it has dozens of fixes put in cumulatively to solve issues found.

The community is glad to help, but make sure you make the most of other people's time they contribute by attempting the easy fixes like upgrading first.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...