A Splunk instance has crashed, but no crash log was generated. There is an attempt to determine what user activity caused the crash by running the following search:
What does searching for closed_txn=0 do in this search?
Closed transactions? In Splunk? Sounds like a game of Tetris gone horribly wrong. But seriously, the closed_txn=0 is probably the key to figuring out this crash.
Ah, the closed_txn=0 must be looking for an instance where Splunk didn't have a chance to gracefully close out its processes. Hopefully that narrows down the investigation.
The closed_txn=0 filter sounds like it's looking for situations where Splunk wasn't properly shut down. Probably a good clue to dig into what caused the crash.
Tyra
2 months agoLinwood
26 days agoJunita
1 months agoCyril
1 months agoLang
2 months agoKristofer
1 months agoElouise
2 months agoArt
2 months agoBenedict
3 months agoLorenza
2 months agoFausto
2 months agoMattie
2 months agoMalinda
3 months agoBlair
2 months agoSolange
2 months agoRegenia
3 months agoStephanie
3 months agoBrendan
3 months agoLoreta
4 months agoKatina
4 months ago