A Splunk instance has crashed, but no crash log was generated. There is an attempt to determine what user activity caused the crash by running the following search:
What does searching for closed_txn=0 do in this search?
Closed transactions? In Splunk? Sounds like a game of Tetris gone horribly wrong. But seriously, the closed_txn=0 is probably the key to figuring out this crash.
Ah, the closed_txn=0 must be looking for an instance where Splunk didn't have a chance to gracefully close out its processes. Hopefully that narrows down the investigation.
The closed_txn=0 filter sounds like it's looking for situations where Splunk wasn't properly shut down. Probably a good clue to dig into what caused the crash.
Tyra
2 months agoLinwood
7 days agoJunita
13 days agoCyril
21 days agoLang
2 months agoKristofer
22 days agoElouise
29 days agoArt
1 months agoBenedict
2 months agoLorenza
1 months agoFausto
1 months agoMattie
2 months agoMalinda
2 months agoBlair
29 days agoSolange
1 months agoRegenia
2 months agoStephanie
2 months agoBrendan
3 months agoLoreta
3 months agoKatina
3 months ago