Troubleshooting
Problem
This Technote provides assistance if you receive the following message in IBM InfoSphere Guardium:
Nanny process error condition The nanny process killed the sniffer. VmData was
Symptom
Message similar to the one below is reported one or more times in Guardium system log (messages) or Alerts:
Nanny process error condition The nanny process killed the sniffer. VmData was 2466500 and was over the limit.
Cause
The sniffer memory usage reached over 90% of the available memory and the nanny process has restarted it, which is expected behavior of the product.
Resolving The Problem
If you are observing this message frequently, there is too much traffic coming to the appliance. Reduce traffic to this appliance to resolve this message. For example, you may move some STAPs to a collector with less load, ignore some traffic in your policy, or implement Load Balancing to spread the traffic among more than one collector.
If the message is observed on very few occasions, it is most likely a momentary spike in traffic. To resolve the message, identify the reason for the spike and avoid the trigger. For example, you can review which processes were running at that time, identify the ones generating more traffic. If message always coincide with a particular process or processes running, reduce the concurrent traffic at that time. For example, you can move heaviest process to run at a different time, or ignore some of this traffic through the policy.
Was this topic helpful?
Document Information
Modified date:
16 June 2018
UID
swg21664056