Out of memory error and erroneous application restarted

38750055 - Out of Memory: system restored, erroneous application has been restarted.

Explanation

An application or service ran out of memory and was restarted. Out of memory issues are commonly caused by software issues or user-defined queries.

User response

Review the following resolutions:
  • Review the error message that is written to the /var/log/qradar.log file to determine which component failed.
  • If the Ariel proxy server is searching through large amounts of data or is using a grouping option that generates unique values in the search results, reduce the number of unique values or reduce the time frame of the search.
  • If the accumulator is generating a time series graph with many aggregated unique values, reduce the size of the query.
  • If a protocol-based log source is recently enabled, decrease the polling period to reduce the data queried. If multiple protocol-based log sources are running at the same time, stagger the start times.
  • If a rule recently changed to track unique properties over long periods of time, reduce the time frame by half or reduce the number of matching events by adding another filter.