A Splunk instance has crashed, but no crash log was generated. There is an attempt to determine what user activity caused the crash by running the following search:
What does searching for closed_txn=0 do in this search?
Closed transactions? In Splunk? Sounds like a game of Tetris gone horribly wrong. But seriously, the closed_txn=0 is probably the key to figuring out this crash.
Ah, the closed_txn=0 must be looking for an instance where Splunk didn't have a chance to gracefully close out its processes. Hopefully that narrows down the investigation.
The closed_txn=0 filter sounds like it's looking for situations where Splunk wasn't properly shut down. Probably a good clue to dig into what caused the crash.
Tyra
1 months agoJunita
Cyril
8 days agoLang
1 months agoKristofer
9 days agoElouise
16 days agoArt
1 months agoBenedict
2 months agoLorenza
28 days agoFausto
1 months agoMattie
1 months agoMalinda
2 months agoBlair
16 days agoSolange
23 days agoRegenia
1 months agoStephanie
1 months agoBrendan
2 months agoLoreta
2 months agoKatina
2 months ago