<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: forwarders restarting in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/forwarders-restarting/m-p/322685#M19827</link>
    <description>&lt;P&gt;On the face of it, that looks like someone changed an entry in serverclass.conf at some point previously, and at 15:46  the deployment server restarted, pushing out the changes to your deployment clients.&lt;/P&gt;

&lt;P&gt;Take a look at the logs on your DS, and see if you can work out if the deployment server was reloaded by hand, or restarted for some other reason&lt;/P&gt;</description>
    <pubDate>Mon, 22 Jan 2018 15:24:26 GMT</pubDate>
    <dc:creator>nickhills</dc:creator>
    <dc:date>2018-01-22T15:24:26Z</dc:date>
    <item>
      <title>forwarders restarting</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/forwarders-restarting/m-p/322684#M19826</link>
      <description>&lt;P&gt;Can anyone think of a reason that might cause all 32 of my Universal Forwarders to restart within a minute of 3:46 PM on Friday?  The first mention of this in all splunkd logs is the essentially the same &lt;/P&gt;

&lt;P&gt;01-19-2018 15:46:48.460 -0500 INFO  DeployedServerclass - Serverclass=Airwatch is uninstalling app=E:\SplunkUniversalForwarder\etc\apps\IIS&lt;BR /&gt;
01-19-2018 15:46:48.460 -0500 INFO  DeployedApplication - Removing app=IIS at='E:\SplunkUniversalForwarder\etc\apps\IIS'&lt;BR /&gt;
01-19-2018 15:46:48.460 -0500 INFO  DeployedServerclass - Serverclass=Airwatch is uninstalling app=E:\SplunkUniversalForwarder\etc\apps\Perfmon&lt;BR /&gt;
01-19-2018 15:46:48.460 -0500 INFO  DeployedApplication - Removing app=Perfmon at='E:\SplunkUniversalForwarder\etc\apps\Perfmon'&lt;BR /&gt;
01-19-2018 15:46:48.460 -0500 INFO  DeployedServerclass - Serverclass=Airwatch is uninstalling app=E:\SplunkUniversalForwarder\etc\apps\WinEvt_Logs&lt;BR /&gt;
01-19-2018 15:46:48.460 -0500 INFO  DeployedApplication - Removing app=WinEvt_Logs at='E:\SplunkUniversalForwarder\etc\apps\WinEvt_Logs'&lt;BR /&gt;
01-19-2018 15:46:48.491 -0500 WARN  DC:DeploymentClient - Restarting Splunkd...&lt;/P&gt;

&lt;P&gt;There is nothing in any of the Windows logs that show anything &lt;BR /&gt;
 unusual happening at this time.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:45:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/forwarders-restarting/m-p/322684#M19826</guid>
      <dc:creator>JarrettM</dc:creator>
      <dc:date>2020-09-29T17:45:59Z</dc:date>
    </item>
    <item>
      <title>Re: forwarders restarting</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/forwarders-restarting/m-p/322685#M19827</link>
      <description>&lt;P&gt;On the face of it, that looks like someone changed an entry in serverclass.conf at some point previously, and at 15:46  the deployment server restarted, pushing out the changes to your deployment clients.&lt;/P&gt;

&lt;P&gt;Take a look at the logs on your DS, and see if you can work out if the deployment server was reloaded by hand, or restarted for some other reason&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2018 15:24:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/forwarders-restarting/m-p/322685#M19827</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2018-01-22T15:24:26Z</dc:date>
    </item>
    <item>
      <title>Re: forwarders restarting</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/forwarders-restarting/m-p/322686#M19828</link>
      <description>&lt;P&gt;Thanks but that doesn't seem to be it. Server.conf isn't being deployed in any of the apps and the Deployment Server did not restart.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2018 16:19:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/forwarders-restarting/m-p/322686#M19828</guid>
      <dc:creator>JarrettM</dc:creator>
      <dc:date>2018-01-22T16:19:33Z</dc:date>
    </item>
    <item>
      <title>Re: forwarders restarting</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/forwarders-restarting/m-p/322687#M19829</link>
      <description>&lt;P&gt;Try searching for:&lt;BR /&gt;
&lt;CODE&gt;index=_internal sourctype=splunkd "DeploymentServer - Attempting to reload entire DS"&lt;/CODE&gt;&lt;BR /&gt;
5+/- minutes around the time in question&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2018 16:36:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/forwarders-restarting/m-p/322687#M19829</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2018-01-22T16:36:55Z</dc:date>
    </item>
    <item>
      <title>Re: forwarders restarting</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/forwarders-restarting/m-p/322688#M19830</link>
      <description>&lt;P&gt;Yes. In that minute all my server classes and apps have events similar to this one:&lt;/P&gt;

&lt;P&gt;1/19/18&lt;BR /&gt;
3:46:22.873 PM&lt;BR /&gt;&lt;BR /&gt;
01-19-2018 15:46:22.873 -0500 INFO  DeploymentServer - Attempting to reload serverclass='Airwatch'; reason='(app=WinEvt_Logs) DeploymentServer::deinstallApplication'&lt;BR /&gt;
host =  HQTM-USPLNK-401 source =    E:\Splunk\var\log\splunk\splunkd.log sourcetype =   splunkd&lt;/P&gt;

&lt;P&gt;But that still begs the question of WHY the Deployment Splunk server decided to reload and reinstall all the classes and apps.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2018 17:05:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/forwarders-restarting/m-p/322688#M19830</guid>
      <dc:creator>JarrettM</dc:creator>
      <dc:date>2018-01-22T17:05:20Z</dc:date>
    </item>
    <item>
      <title>Re: forwarders restarting</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/forwarders-restarting/m-p/322689#M19831</link>
      <description>&lt;P&gt;So it looks like your DS is on windows. Do you also use it as a search head, with the windows TA?  At a guess I would say that a change was made in the ta config which triggered the DS to reload its config, and restart the clients. &lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2018 17:20:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/forwarders-restarting/m-p/322689#M19831</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2018-01-22T17:20:20Z</dc:date>
    </item>
    <item>
      <title>Re: forwarders restarting</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/forwarders-restarting/m-p/322690#M19832</link>
      <description>&lt;P&gt;Not using the Windows TA but somthing happened to the indexer at 3:38 PM on Friday. The index.conf file shows it was updated at 3:38:22 and the splunkd log shows these events:&lt;/P&gt;

&lt;P&gt;1/19/18&lt;BR /&gt;
3:38:22.243 PM&lt;BR /&gt;&lt;BR /&gt;
01-19-2018 15:38:22.243 -0500 INFO  IndexProcessor - reloading index config: end&lt;BR /&gt;
host =  HQTM-USPLNK-401 source =    E:\Splunk\var\log\splunk\splunkd.log sourcetype =   splunkd&lt;BR /&gt;
1/19/18&lt;BR /&gt;
3:38:22.243 PM&lt;BR /&gt;&lt;BR /&gt;
01-19-2018 15:38:22.243 -0500 INFO  IndexProcessor - Reloading index config: shutdown subordinate threads, now restarting&lt;BR /&gt;
host =  HQTM-USPLNK-401 source =    E:\Splunk\var\log\splunk\splunkd.log sourcetype =   splunkd&lt;BR /&gt;
1/19/18&lt;BR /&gt;
3:38:22.243 PM&lt;BR /&gt;&lt;BR /&gt;
01-19-2018 15:38:22.243 -0500 INFO  IndexProcessor - reloading index config: start&lt;BR /&gt;
host =  HQTM-USPLNK-401 source =    E:\Splunk\var\log\splunk\splunkd.log sourcetype =   splunkd&lt;BR /&gt;
1/19/18&lt;BR /&gt;
3:38:22.233 PM&lt;BR /&gt;&lt;BR /&gt;
01-19-2018 15:38:22.233 -0500 INFO  IndexerIf - reloading index config: request received&lt;/P&gt;

&lt;P&gt;If any change was made I'm the only one who could have done it. We are just in the process of initial setup of the Splunk environment and I'm the only one with access.  So it looks like I did something Friday afternoon but I have no idea what. &lt;/P&gt;

&lt;P&gt;Thanks for your help!&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2018 19:14:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/forwarders-restarting/m-p/322690#M19832</guid>
      <dc:creator>JarrettM</dc:creator>
      <dc:date>2018-01-22T19:14:12Z</dc:date>
    </item>
    <item>
      <title>Re: forwarders restarting</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/forwarders-restarting/m-p/322691#M19833</link>
      <description>&lt;P&gt;Hmm the timestamps are close enough to be more than coincidence. &lt;BR /&gt;
You don't have any files named "crash" in your ./splunk/var/log/splunk directory?&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2018 19:40:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/forwarders-restarting/m-p/322691#M19833</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2018-01-22T19:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: forwarders restarting</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/forwarders-restarting/m-p/322692#M19834</link>
      <description>&lt;P&gt;No, no files named crash.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2018 13:00:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/forwarders-restarting/m-p/322692#M19834</guid>
      <dc:creator>JarrettM</dc:creator>
      <dc:date>2018-01-23T13:00:08Z</dc:date>
    </item>
  </channel>
</rss>

