<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk DC:DeploymentClient err=not_connected in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-DC-DeploymentClient-err-not-connected/m-p/488170#M16918</link>
    <description>&lt;P&gt;Troubleshooting Forwarding Problem:&lt;BR /&gt;
Is the management port on the receiver enabled? management port(default to 8089) &lt;BR /&gt;
- you can run a telnet or tcpdump to this port to check the connectivity&lt;/P&gt;

&lt;P&gt;Is a firewall blocking? the firewall should be release on the two way connection from deployment server to UF&lt;/P&gt;

&lt;P&gt;Show all the deployment client messages from the client&lt;BR /&gt;
index=_internal component=DC* host=yourufname | stats count by message&lt;/P&gt;

&lt;P&gt;Show all the deployment messages on the deployment server:&lt;BR /&gt;
index=_internal component=DS* host=yourdeployementsever | stats count by message&lt;/P&gt;

&lt;P&gt;It seems you are having network connection issues. There is similar issue on this answer -&amp;gt; &lt;A href="https://answers.splunk.com/answers/488375/how-to-resolve-errnot-connected-error-in-deploymen.html"&gt;https://answers.splunk.com/answers/488375/how-to-resolve-errnot-connected-error-in-deploymen.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 21 Nov 2019 05:37:35 GMT</pubDate>
    <dc:creator>ivanreis</dc:creator>
    <dc:date>2019-11-21T05:37:35Z</dc:date>
    <item>
      <title>Splunk DC:DeploymentClient err=not_connected</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-DC-DeploymentClient-err-not-connected/m-p/488169#M16917</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;

&lt;P&gt;I have the following problem : &lt;BR /&gt;
A deployment server lost connectivity to all of its clients. If I change the phonehome interval for one of the  clients to any value between 30 to 100 it will eventually connect again. I was wonder if anyone had any thought what would cause this? I can repeat the issue by changing the value back to 300 and it would break the connection again.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;DC:DeploymentClient - channel=tenantService/handshake Will retry sending handshake message to DS; err=not_connected
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;deploymentclient.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[deployment-client]
phoneHomeIntervalInSecs = 300

[target-broker:deploymentServer]
targetUri = x.x.x.x:8089
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 21 Nov 2019 00:53:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-DC-DeploymentClient-err-not-connected/m-p/488169#M16917</guid>
      <dc:creator>matthewssa</dc:creator>
      <dc:date>2019-11-21T00:53:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DC:DeploymentClient err=not_connected</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-DC-DeploymentClient-err-not-connected/m-p/488170#M16918</link>
      <description>&lt;P&gt;Troubleshooting Forwarding Problem:&lt;BR /&gt;
Is the management port on the receiver enabled? management port(default to 8089) &lt;BR /&gt;
- you can run a telnet or tcpdump to this port to check the connectivity&lt;/P&gt;

&lt;P&gt;Is a firewall blocking? the firewall should be release on the two way connection from deployment server to UF&lt;/P&gt;

&lt;P&gt;Show all the deployment client messages from the client&lt;BR /&gt;
index=_internal component=DC* host=yourufname | stats count by message&lt;/P&gt;

&lt;P&gt;Show all the deployment messages on the deployment server:&lt;BR /&gt;
index=_internal component=DS* host=yourdeployementsever | stats count by message&lt;/P&gt;

&lt;P&gt;It seems you are having network connection issues. There is similar issue on this answer -&amp;gt; &lt;A href="https://answers.splunk.com/answers/488375/how-to-resolve-errnot-connected-error-in-deploymen.html"&gt;https://answers.splunk.com/answers/488375/how-to-resolve-errnot-connected-error-in-deploymen.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2019 05:37:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-DC-DeploymentClient-err-not-connected/m-p/488170#M16918</guid>
      <dc:creator>ivanreis</dc:creator>
      <dc:date>2019-11-21T05:37:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DC:DeploymentClient err=not_connected</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-DC-DeploymentClient-err-not-connected/m-p/488171#M16919</link>
      <description>&lt;P&gt;Thanks for the reply! &lt;/P&gt;

&lt;P&gt;I took a look at some of those searches to look for additional messages. &lt;/P&gt;

&lt;P&gt;I don't think it would be the firewall, because if I change the interval to 30 it can eventually connect to the DS and shows up in the Forwarder Management. I still double checked though and see no blocks and the port is also added in firewalld.&lt;/P&gt;

&lt;P&gt;For the deployment server side I didn't get any messages from that that search.&lt;/P&gt;

&lt;P&gt;For the client side I saw the following messages&lt;BR /&gt;
    - Attempted handshake xxx times. Will try to re-subscribe to handshake reply&lt;BR /&gt;
    - Phonehome thread start, intervals: handshakeRetry=60 phonehome=300.0&lt;BR /&gt;
    - channel=deploymentServer/phoneHome/default Will retry sending phonehome to DS; err=not_connected&lt;BR /&gt;
    - channel=tenantService/handshake Will retry handshake message to DS; err=not_connected&lt;/P&gt;

&lt;P&gt;Also I saw some messages that look related.&lt;BR /&gt;
    HTTPPubSubConnection - Unable to parse message from PubSubSvr:&lt;BR /&gt;
    Could no obtain connection, will retry after=xxx.xxx seconds.&lt;/P&gt;

&lt;P&gt;I did a tcpdump and made two different pcaps to look at in wireshark and I kinda wanna say this looks like the client is sending resets before the TLS connection could be finished? Is that what is happening here?&lt;/P&gt;

&lt;P&gt;interval set to 300 (Bad connection to the ds)&lt;BR /&gt;
    client  SYN&lt;BR /&gt;
    ds       SYN, ACK&lt;BR /&gt;
    client  ACK&lt;BR /&gt;
    client  TLSv1.2 Client Hello&lt;BR /&gt;
    ds       ACK&lt;BR /&gt;
    ds       Server Hello, Certificate, Server Hello Done&lt;BR /&gt;
    client  ACK&lt;BR /&gt;
    client  TLSv1.2 Client Key Exchange, Change Cipher Spec, Encrypted Handshake Message&lt;BR /&gt;
    ds       TLSv1.2 New Session Ticket, Change Cipher Spec, Encrypted Handshake Message&lt;BR /&gt;
    client  TLSv1.2 Application Data&lt;BR /&gt;
    ds        ACK&lt;BR /&gt;
    client   FIN, ACK&lt;BR /&gt;
    ds        ACK&lt;BR /&gt;
    ds        TLSv1.2 Application Data&lt;BR /&gt;
    client   RST&lt;BR /&gt;
    ds        TLSv1.2 Application Data&lt;BR /&gt;
    client   RST&lt;BR /&gt;
    ds        TLSv1.2 Encrypted Alert&lt;BR /&gt;
    client   RST&lt;BR /&gt;
    ds        FIN, ACK&lt;BR /&gt;
    client   RST&lt;/P&gt;

&lt;P&gt;interval set to 30 (Good connection to ds)&lt;BR /&gt;
    client  SYN&lt;BR /&gt;
    ds       SYN, ACK&lt;BR /&gt;
    client  ACK&lt;BR /&gt;
    client  TLSv1.2 Client Hello&lt;BR /&gt;
    ds       ACK&lt;BR /&gt;
    ds       Server Hello, Certificate, Server Hello Done&lt;BR /&gt;
    client  ACK&lt;BR /&gt;
    client  TLSv1.2 Client Key Exchange, Change Cipher Spec, Encrypted Handshake Message&lt;BR /&gt;
    ds       TLSv1.2 New Session Ticket, Change Cipher Spec, Encrypted Handshake Message&lt;BR /&gt;
    client  TLSv1.2 Application Data&lt;BR /&gt;
    ds  TLSv1.2 Application Data&lt;BR /&gt;
    ds  TLSv1.2 Application Data&lt;BR /&gt;
    client        ACK&lt;BR /&gt;
    client   FIN, ACK&lt;BR /&gt;
    ds        TLSv1.2 Encrypted Alert&lt;BR /&gt;
    client   RST&lt;BR /&gt;
    ds        FIN, ACK&lt;BR /&gt;
    client   RST&lt;/P&gt;

&lt;P&gt;After all that I went through and started verifying the cipherSuites and sslVersions between the client and ds for web.conf and server.conf which both are using splunks default values.&lt;/P&gt;

&lt;P&gt;Verified also the date on each server because I saw that could be another issue when dealing with TLS connections.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:03:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-DC-DeploymentClient-err-not-connected/m-p/488171#M16919</guid>
      <dc:creator>matthewssa</dc:creator>
      <dc:date>2020-09-30T03:03:37Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DC:DeploymentClient err=not_connected</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-DC-DeploymentClient-err-not-connected/m-p/488172#M16920</link>
      <description>&lt;P&gt;I never played with such configuration before, so try one of those parameters at deployment.conf&lt;/P&gt;

&lt;P&gt;handshakeRetryIntervalInSecs = &lt;BR /&gt;
* This sets the handshake retry frequency, in seconds.&lt;BR /&gt;
* Could be used to tune the initial connection rate on a new server&lt;BR /&gt;
* Default: One fifth of 'phoneHomeIntervalInSecs'&lt;/P&gt;

&lt;P&gt;handshakeReplySubscriptionRetry = &lt;BR /&gt;
* If splunk is unable to complete the handshake, it will retry subscribing to&lt;BR /&gt;
  the handshake channel after this many handshake attempts&lt;BR /&gt;
* Default: 10&lt;/P&gt;

&lt;P&gt;appEventsResyncIntervalInSecs = &lt;BR /&gt;
* This sets the interval at which the client reports back its app state&lt;BR /&gt;
  to the server.&lt;BR /&gt;
* Fractional seconds are allowed.&lt;BR /&gt;
* Default: 10 * 'phoneHomeIntervalInSecs'&lt;/P&gt;

&lt;P&gt;Are you able to deploy apps to those UF clients? &lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2019 05:25:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-DC-DeploymentClient-err-not-connected/m-p/488172#M16920</guid>
      <dc:creator>ivanreis</dc:creator>
      <dc:date>2019-11-22T05:25:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DC:DeploymentClient err=not_connected</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-DC-DeploymentClient-err-not-connected/m-p/518687#M17835</link>
      <description>&lt;P&gt;Hi Matthew,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am receiving the same errors as you, in splunkd.log of the UF.&amp;nbsp; Things were working fine till today, but logs stopped getting indexed today after the IP of the server in which UF is installed got changed. Is your issue resolved? if so, could you please explain what changes you made which fixed the issue.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2020 13:03:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-DC-DeploymentClient-err-not-connected/m-p/518687#M17835</guid>
      <dc:creator>santhoshi</dc:creator>
      <dc:date>2020-09-09T13:03:11Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DC:DeploymentClient err=not_connected</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-DC-DeploymentClient-err-not-connected/m-p/523102#M18015</link>
      <description>&lt;P&gt;Just wanted to post to say that I'm experiencing the exact same behavior. Set&amp;nbsp;&lt;SPAN class="s1"&gt;phoneHomeIntervalInSecs to 600, I get the "&lt;SPAN&gt;err=not_connected" message. If I change it back to 60, it'll work again with no issues.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I also tried playing around with setting&amp;nbsp;&lt;SPAN class="s1"&gt;handshakeRetryIntervalInSecs to a low value (since the docs mention that it is set to "one fifth of&amp;nbsp;phoneHomeIntervalInSecs") but no dice.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Oct 2020 03:27:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-DC-DeploymentClient-err-not-connected/m-p/523102#M18015</guid>
      <dc:creator>obw1r3d</dc:creator>
      <dc:date>2020-10-06T03:27:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DC:DeploymentClient err=not_connected</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-DC-DeploymentClient-err-not-connected/m-p/523179#M18019</link>
      <description>&lt;P&gt;I'm sorry I still have not found the resolution to my issue. I was able to dig deeper at one point and saw timeout messages in the Splunk internal logs. I would also see timeouts when going to the Splunk webpage or any other tools webpage. For some reason though if I move the deployment server to sit outside of our firewall and change the physical ip address of the deployment server to the NAT that was being used on the firewall. All of the Splunk agents can suddenly connect. I believe this to be a network issue, but we have yet to figure out what it is.&amp;nbsp;When I pulled some pcaps I saw every other line was one of the following. TCP Dup ACK, TCP Retransmissions, or TCP Out-of-Order&lt;/P&gt;</description>
      <pubDate>Tue, 06 Oct 2020 13:13:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-DC-DeploymentClient-err-not-connected/m-p/523179#M18019</guid>
      <dc:creator>matthewssa</dc:creator>
      <dc:date>2020-10-06T13:13:38Z</dc:date>
    </item>
  </channel>
</rss>

