Refine your search:

Hello,

I´m having a problem with splunkd service after upgrading to the latest splunk-4.2.4-110225 on Windows Server 2008 R2 Standard SP1, where we´ve had a perfectly working splunk-4.1.6-89596 installation

During the upgrade, I´ve stopped all Splunk services, launched splunk-4.2.4-110225-x64-release.msi and have chosen Auto-Migrate. The installation process has had gone without error, but when I tried to open Splunk web, I have received an error

The splunkd daemon cannot be reached by splunkweb. Check that there are no blocked network ports or that splunkd is still running.

I have had examined log files and found that splunkd is causing errors

Windows Application Log

Faulting application name: splunkd.exe, version: 0.0.0.0, time stamp: 0x4e95b8ac
Faulting module name: KERNELBASE.dll, version: 6.1.7601.17651, time stamp: 0x4e21213c
Exception code: 0xeeab5254
Fault offset: 0x000000000000cacd
Faulting process id: 0x10d0
Faulting application start time: 0x01cca2c1a2f8c8bc
Faulting application path: C:\Program Files\Splunk\bin\splunkd.exe
Faulting module path: C:\Windows\system32\KERNELBASE.dll
Report Id: e477af2c-0eb4-11e1-8d07-18a90576dbe0

ERROR lines from splunkd.log

11-14-2011 13:28:13.836 +0100 ERROR LMStack - failed to load license from file: splunk.license, err - Only pro versions of old licenses are honoured in the new licenser
11-14-2011 13:28:21.932 +0100 ERROR loader - Couldn't find library for: bytequotaprocessor
11-14-2011 13:28:21.932 +0100 ERROR pipeline - Couldn't find library for: bytequotaprocessor
11-14-2011 13:28:21.932 +0100 ERROR PipelineComponent - The pipeline indexerPipe threw an exception during initialize
11-14-2011 13:28:21.932 +0100 ERROR TcpInputProc - Indexer failed to start, will not continue.
11-14-2011 13:28:21.932 +0100 ERROR pipeline - Indexer failed to start, will not continue.
11-14-2011 13:28:21.932 +0100 ERROR PipelineComponent - The pipeline tcp threw an exception during initialize
11-14-2011 13:28:21.932 +0100 ERROR UDPInputProcessor - Indexer failed to start, will not continue.
11-14-2011 13:28:21.932 +0100 ERROR pipeline - Indexer failed to start, will not continue.
11-14-2011 13:28:21.932 +0100 ERROR PipelineComponent - The pipeline udp threw an exception during initialize
11-14-2011 13:28:21.932 +0100 ERROR ExecProcessor - Indexer failed to start, will not continue.
11-14-2011 13:28:21.932 +0100 ERROR pipeline - Indexer failed to start, will not continue.
11-14-2011 13:28:21.932 +0100 ERROR PipelineComponent - The pipeline exec threw an exception during initialize
11-14-2011 13:28:21.932 +0100 ERROR FSChangeManagerProcessor - Indexer failed to start, will not continue.
11-14-2011 13:28:21.932 +0100 ERROR pipeline - Indexer failed to start, will not continue.
11-14-2011 13:28:21.932 +0100 ERROR PipelineComponent - The pipeline fschangemanager threw an exception during initialize
11-14-2011 13:28:21.932 +0100 ERROR ArchiveProcessor - Indexer failed to start, will not continue.
11-14-2011 13:28:21.932 +0100 ERROR pipeline - Indexer failed to start, will not continue.
11-14-2011 13:28:21.932 +0100 ERROR PipelineComponent - The pipeline archivePipe threw an exception during initialize
11-14-2011 13:28:21.948 +0100 ERROR WinEventLogInputProcessor - Indexer failed to start, will not continue.
11-14-2011 13:28:21.948 +0100 ERROR pipeline - Indexer failed to start, will not continue.
11-14-2011 13:28:21.948 +0100 ERROR PipelineComponent - The pipeline wineventlog threw an exception during initialize
11-14-2011 13:28:21.948 +0100 ERROR TailingProcessor - Indexer failed to start, will not continue.

splunkd-exe-crash log

[build 110225] 2011-11-14 13:28:21
C++ exception: object@[0x0000000003D1F1C8], type@[0x00000001414E96F0]
Exception is Non-continuable
Exception address: [0x000007FEFD73CACD]
Crashing thread: MainTailingThread
MxCsr:  [0x0000000000001F80]
SegDs:  [0x000000000000002B]
SegEs:  [0x000000000000002B]
SegFs:  [0x0000000000000053]
SegGs:  [0x000000000000002B]
SegSs:  [0x000000000000002B]
SegCs:  [0x0000000000000033]
EFlags:  [0x0000000000000202]
Rsp:  [0x0000000003D1EFF0]
Rip:  [0x000007FEFD73CACD] RaiseException + 61/80
Dr0:  [0x0000000000B70080]
Dr1:  [0x0000000000000000]
Dr2:  [0x0000000000B70278]
Dr3:  [0x0000000077635410]
Dr6:  [0x0000000000000000]
Dr7:  [0x0000000000000030]
Rax:  [0x00000000502CAA01]
Rcx:  [0x0000000003D1E9E0]
Rdx:  [0x00000000000000D0]
Rbx:  [0x00000001414E96F0]
Rbp:  [0x0000000000000000]
Rsi:  [0x0000000141511738]
Rdi:  [0x0000000140F30C00]
R8:  [0x0000000000000000]
R9:  [0x0000000000000000]
R10:  [0x0000000140000000]
R11:  [0x0000000003D1F030]
R12:  [0x0000000140F41704]
R13:  [0x00000000036FA440]
R14:  [0x0000000000000000]
R15:  [0x0000000000000000]
DebugControl:  [0x0000000000000000]
LastBranchToRip:  [0x0000000000000040]
LastBranchFromRip:  [0x0000000000CC0000]
LastExceptionToRip:  [0x000000000000002F]
LastExceptionFromRip:  [0x0000000000000030]

OS: Windows
Arch: x86-64

Backtrace:
[0x000007FEFD73CACD] RaiseException + 61/80
[0x0000000072D1B164] CxxThrowException + 196/464
[0x00000001404ABDC4] ?
[0x00000001400DAA83] ?
[0x00000001400DB00C] ?
[0x0000000140810822] ?
[0x0000000140003AC7] ?
[0x0000000072CE37D7] endthreadex + 71/272
[0x0000000072CE3894] endthreadex + 260/272
[0x000000007741652D] BaseThreadInitThunk + 13/96
[0x000000007754C521] RtlUserThreadStart + 33/1024
Crash dump written to: C:\Program Files\Splunk\var\log\splunk\C__Program     Files_Splunk_bin_splunkd_exe_crash-2011-11-14-13-28-21.dmp

SPLUNK2 /6.1 Service Pack 1
Threads running: 17
argv: [Splunkd -p 8089]
terminating...

Any help appreciated!!!

asked 14 Nov '11, 04:58

a2novak2's gravatar image

a2novak2
213
accept rate: 0%

edited 24 Nov '11, 00:38

Be the first one to answer this question!
toggle preview

Follow this question

Log In to enable email subscriptions

RSS:

Answers

Answers + Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "Title")
  • image?![alt text](/path/img.jpg "Title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Tags:

×59
×47
×2

Asked: 14 Nov '11, 04:58

Seen: 1,046 times

Last updated: 24 Nov '11, 00:39

Copyright © 2005-2012 Splunk Inc. All rights reserved.