<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why does splunkd_access.log burst events on our Unix universal forwarder for no reason, using up 17% CPU? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-splunkd-access-log-burst-events-on-our-Unix-universal/m-p/259539#M49822</link>
    <description>&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/146813/why-cpu-spikes-and-stays-at-100-installing-universal-forwarder-on-server-2012-r2.html"&gt;Why CPU spikes and stays at 100% installing universal forwarder on server 2012 R2?&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;A good one at - &lt;A href="https://answers.splunk.com/answers/5400/high-cpu-usage-on-splunk-forwarder.html"&gt;High cpu usage on splunk forwarder&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;About &lt;CODE&gt;Checksum for seekptr didn't match, will re-read entire file='access.log'&lt;/CODE&gt; - &lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/102356/explanation-of-checksum-for-seekptr-didnt-match-will-re-read-entire-file.html"&gt;Explanation of Checksum for seekptr didn't match, will re-read entire file&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 13 Jul 2016 21:25:23 GMT</pubDate>
    <dc:creator>ddrillic</dc:creator>
    <dc:date>2016-07-13T21:25:23Z</dc:date>
    <item>
      <title>Why does splunkd_access.log burst events on our Unix universal forwarder for no reason, using up 17% CPU?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-splunkd-access-log-burst-events-on-our-Unix-universal/m-p/259537#M49820</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;I've set up a Unix universal forwarder to monitor text-based files on a system.&lt;BR /&gt;
I always thought forwarders have a small footprint, but my forwarder currently eats up 17% of the CPU of the machine it's installed on.&lt;/P&gt;

&lt;P&gt;I checked everything and found something weird.&lt;BR /&gt;
Splunkd_access.log writes approx. 2 MB of data every second. Splunkd_access.log rolls about every two minutes.&lt;BR /&gt;
Splunk-Forwarder-Version: 6.4.1&lt;/P&gt;

&lt;P&gt;Splunkd_access.log shows the following constant output:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;-somedate-    "POST    /services/shcluster/member/consensus/pseudoid/raft_request_vote?output_mode=json    HTTP/1.1" 401 71 - - - 0ms
-somedate-    "POST    /services/shcluster/member/consensus/pseudoid/raft_request_vote?output_mode=json    HTTP/1.1" 401 71 - - - 0ms
-somedate-    "POST    /services/shcluster/member/consensus/pseudoid/raft_request_vote?output_mode=json    HTTP/1.1" 401 71 - - - 0ms
-somedate-    "POST    /services/shcluster/member/consensus/pseudoid/raft_request_vote?output_mode=json    HTTP/1.1" 401 71 - - - 0ms
-somedate-    "POST    /services/shcluster/member/consensus/pseudoid/raft_request_vote?output_mode=json    HTTP/1.1" 401 71 - - - 0ms
-somedate-    "POST    /services/shcluster/member/consensus/pseudoid/raft_request_vote?output_mode=json    HTTP/1.1" 401 71 - - - 0ms
-somedate-    "POST    /services/shcluster/member/consensus/pseudoid/raft_request_vote?output_mode=json    HTTP/1.1" 401 71 - - - 0ms
-somedate-    "POST    /services/shcluster/member/consensus/pseudoid/raft_request_vote?output_mode=json    HTTP/1.1" 401 71 - - - 0ms
-somedate-    "POST    /services/shcluster/member/consensus/pseudoid/raft_request_vote?output_mode=json    HTTP/1.1" 401 71 - - - 0ms
-somedate-    "POST    /services/shcluster/member/consensus/pseudoid/raft_request_vote?output_mode=json    HTTP/1.1" 401 71 - - - 0ms
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;While splunkd.log throws me this repeatedly:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;-somedate- INFO  WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/splunkforwarder/var/log/splunk/splunkd_access.log'.
-somedate- INFO  WatchedFile - Will begin reading at offset=0 for file='/opt/splunkforwarder/var/log/splunk/splunkd_access.log'.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;HR /&gt;

&lt;P&gt;Anyone here who has seen this strange behavior before?&lt;BR /&gt;
Thanks in advance!&lt;/P&gt;

&lt;P&gt;Best regards,&lt;BR /&gt;
pyro_wood&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:13:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-splunkd-access-log-burst-events-on-our-Unix-universal/m-p/259537#M49820</guid>
      <dc:creator>horsefez</dc:creator>
      <dc:date>2020-09-29T10:13:44Z</dc:date>
    </item>
    <item>
      <title>Re: Why does splunkd_access.log burst events on our Unix universal forwarder for no reason, using up 17% CPU?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-splunkd-access-log-burst-events-on-our-Unix-universal/m-p/259538#M49821</link>
      <description>&lt;P&gt;Very weird... I'd scrutinize for any shcluster related config&lt;BR /&gt;
    /opt/splunkforwarder/bin/splunk btool --debug server list | less&lt;BR /&gt;
Search for any mention of shcluster&lt;/P&gt;

&lt;P&gt;Other than that you might have a bug on your hands. &lt;/P&gt;

&lt;P&gt;Do you have multiple systems expressing this behavior?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2016 20:33:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-splunkd-access-log-burst-events-on-our-Unix-universal/m-p/259538#M49821</guid>
      <dc:creator>muebel</dc:creator>
      <dc:date>2016-07-13T20:33:34Z</dc:date>
    </item>
    <item>
      <title>Re: Why does splunkd_access.log burst events on our Unix universal forwarder for no reason, using up 17% CPU?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-splunkd-access-log-burst-events-on-our-Unix-universal/m-p/259539#M49822</link>
      <description>&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/146813/why-cpu-spikes-and-stays-at-100-installing-universal-forwarder-on-server-2012-r2.html"&gt;Why CPU spikes and stays at 100% installing universal forwarder on server 2012 R2?&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;A good one at - &lt;A href="https://answers.splunk.com/answers/5400/high-cpu-usage-on-splunk-forwarder.html"&gt;High cpu usage on splunk forwarder&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;About &lt;CODE&gt;Checksum for seekptr didn't match, will re-read entire file='access.log'&lt;/CODE&gt; - &lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/102356/explanation-of-checksum-for-seekptr-didnt-match-will-re-read-entire-file.html"&gt;Explanation of Checksum for seekptr didn't match, will re-read entire file&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2016 21:25:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-splunkd-access-log-burst-events-on-our-Unix-universal/m-p/259539#M49822</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2016-07-13T21:25:23Z</dc:date>
    </item>
    <item>
      <title>Re: Why does splunkd_access.log burst events on our Unix universal forwarder for no reason, using up 17% CPU?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-splunkd-access-log-burst-events-on-our-Unix-universal/m-p/259540#M49823</link>
      <description>&lt;P&gt;The splunkd.log part is benign, just a sign of log rotation happening in splunkd_access.log.&lt;/P&gt;

&lt;P&gt;The access logs suggest someone is trying to make the forwarder vote in a search head cluster captain election.&lt;BR /&gt;
That makes no sense whatsoever, make sure no SHC is configured with this machine as a member on top of what @muebel said.&lt;BR /&gt;
The client IP listed in the access log should be a good clue as to where to look for misconfiguration first.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2016 22:56:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-splunkd-access-log-burst-events-on-our-Unix-universal/m-p/259540#M49823</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2016-07-13T22:56:11Z</dc:date>
    </item>
    <item>
      <title>Re: Why does splunkd_access.log burst events on our Unix universal forwarder for no reason, using up 17% CPU?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-splunkd-access-log-burst-events-on-our-Unix-universal/m-p/259541#M49824</link>
      <description>&lt;P&gt;Thank you muebel and martin_mueller for your suggestions.&lt;BR /&gt;
Martin is indeed right with his assumption. This machine was previously configured as part of a search head cluster. But splunk had been deleted since.&lt;/P&gt;

&lt;P&gt;Anyway... I now ordered a complete wipe of the machine and a reset and then it should be all fine again.&lt;/P&gt;

&lt;P&gt;Thanks to you two for the quick responses &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2016 16:55:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-splunkd-access-log-burst-events-on-our-Unix-universal/m-p/259541#M49824</guid>
      <dc:creator>horsefez</dc:creator>
      <dc:date>2016-07-14T16:55:00Z</dc:date>
    </item>
    <item>
      <title>Re: Why does splunkd_access.log burst events on our Unix universal forwarder for no reason, using up 17% CPU?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-splunkd-access-log-burst-events-on-our-Unix-universal/m-p/259542#M49825</link>
      <description>&lt;P&gt;Thanks for nothing. Links don't help either. Better read the question first next time!&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2016 16:56:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-splunkd-access-log-burst-events-on-our-Unix-universal/m-p/259542#M49825</guid>
      <dc:creator>horsefez</dc:creator>
      <dc:date>2016-07-14T16:56:10Z</dc:date>
    </item>
    <item>
      <title>Re: Why does splunkd_access.log burst events on our Unix universal forwarder for no reason, using up 17% CPU?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-splunkd-access-log-burst-events-on-our-Unix-universal/m-p/259543#M49826</link>
      <description>&lt;P&gt;Make sure no other cluster members remember this forwarder as a former member on top of cleaning up the forwarder itself.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2016 04:00:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-splunkd-access-log-burst-events-on-our-Unix-universal/m-p/259543#M49826</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2016-07-15T04:00:16Z</dc:date>
    </item>
  </channel>
</rss>

