<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: UF's are disappearing from ForwarderManagement in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/579579#M25132</link>
    <description>And your DS's splunk version is the highest or equal one than any other nodes UF+servers?&lt;BR /&gt;&lt;BR /&gt;What "splunk btool deploymentclient list --debug" said? Are those values and places what you are expecting? And how about "splunk show deploy-poll" ?&lt;BR /&gt;&lt;BR /&gt;I assume that telnet/curl from DC to DS:8089 (or what ever your mgmt port is) is working?&lt;BR /&gt;&lt;BR /&gt;Those DCs are in same DC or behind VPN?&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Thu, 30 Dec 2021 10:48:39 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2021-12-30T10:48:39Z</dc:date>
    <item>
      <title>Why are UF's are disappearing from ForwarderManagement</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/579443#M25124</link>
      <description>&lt;P&gt;Dear Splunkers,&lt;/P&gt;
&lt;P&gt;Can you please assist with following problem:&lt;/P&gt;
&lt;P&gt;We have more 20 UF's installed on windows machines, all of them have deployment server set, and were visible in Forwarder Management. But in some time all of them disappeared from FM and are appearing from time to time there.&lt;/P&gt;
&lt;P&gt;I have tried to delete $SPLUNK_HOME/etc/instance.cfg&amp;nbsp; on several forwarders and restarted them but problem was not fixed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any ideas how to fix it and what can cause such strange behavior?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Eugene&lt;/P&gt;</description>
      <pubDate>Mon, 14 Feb 2022 15:09:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/579443#M25124</guid>
      <dc:creator>Gene</dc:creator>
      <dc:date>2022-02-14T15:09:25Z</dc:date>
    </item>
    <item>
      <title>Re: UF's are disappearing from ForwarderManagement</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/579564#M25127</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Are they disappeared permanently or only time by time? If last then you must remember that when you restart or do some other configuration changes on DS side, it needs that DCs (UF's) will phone home again before you can see those there again?&lt;/P&gt;&lt;P&gt;Have you MC in place and if are they there under Forwarders (enable forwarder management first).&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2021 09:31:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/579564#M25127</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-12-30T09:31:51Z</dc:date>
    </item>
    <item>
      <title>Re: UF's are disappearing from ForwarderManagement</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/579573#M25128</link>
      <description>&lt;P&gt;Hi, and thank you for response.&lt;/P&gt;&lt;P&gt;But actually situation is following:&lt;/P&gt;&lt;P&gt;we set up forwarders=&amp;gt;set DS=&amp;gt; they appear in console=&amp;gt; they disappear from console=&amp;gt; some of them sometimes appear, but not for a long time&lt;/P&gt;&lt;P&gt;I suppose that this can be connected to some firewall settings, but client assures that they can't find any connections that were blocked during that time. Also UF logs show:&lt;BR /&gt;INFO DC:DeploymentClient - channel=tenantService/handshake Will retry sending handshake message to DS; err=not_connected&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2021 10:35:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/579573#M25128</guid>
      <dc:creator>Gene</dc:creator>
      <dc:date>2021-12-30T10:35:17Z</dc:date>
    </item>
    <item>
      <title>Re: UF's are disappearing from ForwarderManagement</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/579574#M25129</link>
      <description>And you have only one DS, not several behind LB?</description>
      <pubDate>Thu, 30 Dec 2021 10:37:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/579574#M25129</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-12-30T10:37:30Z</dc:date>
    </item>
    <item>
      <title>Re: UF's are disappearing from ForwarderManagement</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/579575#M25130</link>
      <description>&lt;P&gt;Yes, correct.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2021 10:38:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/579575#M25130</guid>
      <dc:creator>Gene</dc:creator>
      <dc:date>2021-12-30T10:38:57Z</dc:date>
    </item>
    <item>
      <title>Re: UF's are disappearing from ForwarderManagement</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/579577#M25131</link>
      <description>&lt;P&gt;I mean only one&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2021 10:41:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/579577#M25131</guid>
      <dc:creator>Gene</dc:creator>
      <dc:date>2021-12-30T10:41:54Z</dc:date>
    </item>
    <item>
      <title>Re: UF's are disappearing from ForwarderManagement</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/579579#M25132</link>
      <description>And your DS's splunk version is the highest or equal one than any other nodes UF+servers?&lt;BR /&gt;&lt;BR /&gt;What "splunk btool deploymentclient list --debug" said? Are those values and places what you are expecting? And how about "splunk show deploy-poll" ?&lt;BR /&gt;&lt;BR /&gt;I assume that telnet/curl from DC to DS:8089 (or what ever your mgmt port is) is working?&lt;BR /&gt;&lt;BR /&gt;Those DCs are in same DC or behind VPN?&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 30 Dec 2021 10:48:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/579579#M25132</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-12-30T10:48:39Z</dc:date>
    </item>
    <item>
      <title>Re: UF's are disappearing from ForwarderManagement</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/579589#M25133</link>
      <description>&lt;P&gt;Versions are the same.&lt;/P&gt;&lt;P&gt;btool and show deploy-poll show correct values.&lt;/P&gt;&lt;P&gt;telnet -&amp;nbsp; clarifying with client, cause do not have access to endpoints where forwarders are installed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;and clients are in the same subnet, no VPN is used.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2021 11:16:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/579589#M25133</guid>
      <dc:creator>Gene</dc:creator>
      <dc:date>2021-12-30T11:16:01Z</dc:date>
    </item>
    <item>
      <title>Re: UF's are disappearing from ForwarderManagement</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/579654#M25134</link>
      <description>&lt;P&gt;You should try from UF side to DS curl/telnet. All traffic between those are initiated by DC not DS!&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;curl -vkI https://&amp;lt;Your DS fqdn&amp;gt;:8089&lt;/LI-CODE&gt;&lt;P&gt;Above command show HEAD part of response with debug information.&lt;/P&gt;&lt;P&gt;For security reason it's good to disable 8089 (management) port on UF unless you are regularly using it from scripts etc. on UF side.&lt;/P&gt;&lt;P&gt;How about host based firewalls?&lt;/P&gt;&lt;P&gt;r. Ismo&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Dec 2021 08:40:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/579654#M25134</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-12-31T08:40:16Z</dc:date>
    </item>
    <item>
      <title>Re: UF's are disappearing from ForwarderManagement</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/579687#M25135</link>
      <description>&lt;P&gt;Please check if your deployment server is not restarting/crashing.&lt;/P&gt;&lt;P&gt;The deployment server won't show any UF clients if it just restarted. Only after de UF clients called home it will pop-up.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Dec 2021 11:15:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/579687#M25135</guid>
      <dc:creator>teunlaan</dc:creator>
      <dc:date>2021-12-31T11:15:18Z</dc:date>
    </item>
    <item>
      <title>Re: UF's are disappearing from ForwarderManagement</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/580570#M25162</link>
      <description>&lt;P&gt;DS is not restarting or crashing, the thing is that clients connect only once and after they can't reach DS. I assume that problem is with Firewall rules but for now client is checking this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jan 2022 09:51:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/580570#M25162</guid>
      <dc:creator>Gene</dc:creator>
      <dc:date>2022-01-11T09:51:42Z</dc:date>
    </item>
    <item>
      <title>Re: UF's are disappearing from ForwarderManagement</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/580572#M25164</link>
      <description>If DC can connect to DS once after start, it's hard to think that the issue is in FW. Of course if you have L7/NG level FW then it's possible...&lt;BR /&gt;Can it be that your DC polling time is too long?</description>
      <pubDate>Tue, 11 Jan 2022 10:10:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/580572#M25164</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-01-11T10:10:34Z</dc:date>
    </item>
    <item>
      <title>Re: UF's are disappearing from ForwarderManagement</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/580581#M25166</link>
      <description>&lt;P&gt;Not necessarily if yu ou can get a copy of the uf logs after they have connected once to DS can shed more light on this, once there was an app that caused this too. So n number of possibilities. Logs can on tell what's happening..&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jan 2022 11:32:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/580581#M25166</guid>
      <dc:creator>SinghK</dc:creator>
      <dc:date>2022-01-11T11:32:56Z</dc:date>
    </item>
    <item>
      <title>Re: UF's are disappearing from ForwarderManagement</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/580582#M25167</link>
      <description>&lt;P&gt;Actually all settings are default, we didn't touch polling time. I will try to play with that also, thx&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jan 2022 11:38:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/580582#M25167</guid>
      <dc:creator>Gene</dc:creator>
      <dc:date>2022-01-11T11:38:04Z</dc:date>
    </item>
    <item>
      <title>Re: UF's are disappearing from ForwarderManagement</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/580583#M25168</link>
      <description>&lt;P&gt;Thx for the suggestion, but the strangest thing is that all forwarders are sending data as expected also to indexer, that is configured as DS. But not seen in console.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jan 2022 11:41:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/580583#M25168</guid>
      <dc:creator>Gene</dc:creator>
      <dc:date>2022-01-11T11:41:11Z</dc:date>
    </item>
    <item>
      <title>Re: UF's are disappearing from ForwarderManagement</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/580585#M25169</link>
      <description>Polling from DC - DS use port 8089 and sending data is using 9997 (or 9998 TLS) by default.</description>
      <pubDate>Tue, 11 Jan 2022 11:47:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/580585#M25169</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-01-11T11:47:03Z</dc:date>
    </item>
    <item>
      <title>Re: UF's are disappearing from ForwarderManagement</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/580587#M25170</link>
      <description>&lt;P class="lia-align-left"&gt;Yes, correct. That is why I suspect that some firewall rules are blocking this connection, maybe some beckoning rules....&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jan 2022 11:55:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/580587#M25170</guid>
      <dc:creator>Gene</dc:creator>
      <dc:date>2022-01-11T11:55:50Z</dc:date>
    </item>
    <item>
      <title>Re: UF's are disappearing from ForwarderManagement</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/580595#M25171</link>
      <description>&lt;P&gt;So what is the internal log of the UF's telling?&amp;nbsp; Do they try connect but it fails, or don't they even try.&lt;/P&gt;&lt;P&gt;You state they connect 1 time and than it stops., what is strange.&lt;/P&gt;&lt;P&gt;Check if you arn't&amp;nbsp; pushing a deploymentclient.conf.&lt;/P&gt;&lt;P&gt;And is the config you're pushing restarting the Forwarder? if yes:&amp;nbsp; try changing your serverclass so it does not restart the UF, see if it keeps the conection (maybe something failes&amp;nbsp;@ the restart)&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jan 2022 12:30:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/580595#M25171</guid>
      <dc:creator>teunlaan</dc:creator>
      <dc:date>2022-01-11T12:30:56Z</dc:date>
    </item>
    <item>
      <title>Re: UF's are disappearing from ForwarderManagement</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/580621#M25172</link>
      <description>&lt;P&gt;I have checked logs and still can't find what's wrong:&lt;/P&gt;&lt;P&gt;01-11-2022 14:20:18.073 +0200 INFO DC:HandshakeReplyHandler [13276 HttpClientPollingThread_85591AD8-9097-47F4-B73E-4F63150ACA4D] - Handshake done&lt;/P&gt;&lt;P&gt;01-11-2022 14:21:30.273 +0200 INFO DS_DC_Common [5620 MainThread] - Initializing the PubSub system.&lt;BR /&gt;01-11-2022 14:21:30.273 +0200 INFO DS_DC_Common [5620 MainThread] - Initializing core facilities of PubSub system.&lt;BR /&gt;01-11-2022 14:21:30.335 +0200 WARN HTTPAuthManager [5620 MainThread] - pass4SymmKey length is too short. See pass4SymmKey_minLength under the general stanza in server.conf.&lt;BR /&gt;01-11-2022 14:21:30.335 +0200 INFO HttpPubSubConnection [872 HttpClientPollingThread_85591AD8-9097-47F4-B73E-4F63150ACA4D] - Initial attempt to obtain connection will try after=37.475 seconds.&lt;BR /&gt;01-11-2022 14:21:30.335 +0200 INFO DC:DeploymentClient [5620 MainThread] - Starting phonehome thread.&lt;BR /&gt;01-11-2022 14:21:30.335 +0200 INFO DS_DC_Common [5620 MainThread] - Deployment Client initialized.&lt;BR /&gt;01-11-2022 14:21:30.335 +0200 INFO ServerRoles [5620 MainThread] - Declared role=deployment_client.&lt;BR /&gt;01-11-2022 14:21:30.335 +0200 INFO DS_DC_Common [5620 MainThread] - Deployment Server not available on a dedicated forwarder.&lt;BR /&gt;01-11-2022 14:21:30.335 +0200 INFO DC:PhonehomeThread [6308 PhonehomeThread] - Phonehome thread start, intervals: handshakeRetry=12.0 phonehome=60.0.&lt;BR /&gt;01-11-2022 14:21:30.335 +0200 INFO ClusteringMgr [5620 MainThread] - initing clustering with: ht=60.000 rf=3 sf=2 ct=60.000 st=60.000 rt=60.000 rct=5.000 rst=5.000 rrt=10.000 rmst=600.000 rmrt=600.000 icps=25 sfrt=600.000 pe=1 im=0 ip=0 mob=5 mor=5 mosr=5 pb=5 rep_port= pptr=10 pptrl=100 fznb=10 Empty/Default cluster pass4symmkey=false allow Empty/Default cluster pass4symmkey=true rrt=restart dft=180 abt=600 sbs=1&lt;BR /&gt;01-11-2022 14:21:30.335 +0200 INFO DC:DeploymentClient [6308 PhonehomeThread] - channel=tenantService/handshake Will retry sending handshake message to DS; err=not_connected&lt;/P&gt;&lt;P&gt;01-11-2022 14:21:42.338 +0200 INFO DC:DeploymentClient [6308 PhonehomeThread] - channel=tenantService/handshake Will retry sending handshake message to DS; err=not_connected&lt;BR /&gt;01-11-2022 14:21:54.338 +0200 INFO DC:DeploymentClient [6308 PhonehomeThread] - channel=tenantService/handshake Will retry sending handshake message to DS; err=not_connected&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jan 2022 15:00:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/580621#M25172</guid>
      <dc:creator>Gene</dc:creator>
      <dc:date>2022-01-11T15:00:12Z</dc:date>
    </item>
    <item>
      <title>Re: UF's are disappearing from ForwarderManagement</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/580622#M25173</link>
      <description>&lt;P&gt;Why are logs complaining about pass4symmkey??&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jan 2022 15:11:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-are-UF-s-are-disappearing-from-ForwarderManagement/m-p/580622#M25173</guid>
      <dc:creator>SinghK</dc:creator>
      <dc:date>2022-01-11T15:11:09Z</dc:date>
    </item>
  </channel>
</rss>

