Getting Data In

Splunk UF crashing frequently 6.3

rsathish47
Contributor

Hi All,

UF is crashing frequently . I didn't find any details in the splunkd logs

VERSION=6.3.0
BUILD=aa7d4b1ccb80
PRODUCT=splunk
PLATFORM=Linux-x86_64

Splunk Error Log:
splunkd: /home/build/build-src/ember/src/pipeline/input/Tailing.h:178: bool StatWrap::isDir() const: Assertion _valid' failed.
2016-09-19 07:10:30.089 +0200 splunkd started (build aa7d4b1ccb80)
splunkd: /home/build/build-src/ember/src/pipeline/input/Tailing.h:178: bool StatWrap::isDir() const: Assertion
_valid' failed.
2016-10-03 08:00:18.048 +0200 splunkd started (build aa7d4b1ccb80)
splunkd: /home/build/build-src/ember/src/pipeline/input/Tailing.h:178: bool StatWrap::isDir() const: Assertion `_valid' failed.
2016-10-17 19:22:31.964 +0200 splunkd started (build aa7d4b1ccb80)

Thanks
Sathish Rangan

Tags (1)
0 Karma

jwelch_splunk
Splunk Employee
Splunk Employee

http://docs.splunk.com/Documentation/Splunk/6.3.1/ReleaseNotes/6.3.1

2015-11-04 SPL-104078, SPL-104017 Splunkd crash due to assertion failure in Tailing.

This appears to be the same issue and is fixed in 6.3.1

I would suggest you upgrade.

dwaddle
SplunkTrust
SplunkTrust

When you hit an assertion or other crash condition, and you are running on something that is not the latest patch level for the release you are on - update first, then seek help from the community and/or support. There have been 8 public releases of Splunk 6.3 over the last year since Splunk 6.3.0 originally dropped.. Currently Splunk 6.3.8 is the latest, and the change logs (http://docs.splunk.com/Documentation/Splunk/6.3.8/ReleaseNotes/6.3.8) show it has dozens of fixes put in cumulatively to solve issues found.

The community is glad to help, but make sure you make the most of other people's time they contribute by attempting the easy fixes like upgrading first.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...