Deployment Architecture

I got a "Streamed search execute failed because" warning message in Splunk? What does this mean?

rsimmons
Splunk Employee
Splunk Employee

During one of my searches, I got this following error message "Streamed search execute failed because: St9bad_alloc". Any ideas on why it would occur and what it means?

Brian_Osburn
Builder

bad_alloc usually means it can't assign memory space for what it needs.

Whats your memory look like on your search head and indexers?

the_wolverine
Champion

Any error along the lines of "Streamed search execute failed ..." is a distributed search error. You'll find this error on the search head, however, it is pointing to some issue at the search peer. If you have multiple search peers, you'll need to investigate which peer triggered this error and then go deeper into why the error was triggered.

The St9bad_alloc might have something to do with a memory/resource issue at the search peer. Need more context.

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...