<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Forwarder ShutdownHandler in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-ShutdownHandler/m-p/487486#M83456</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have set up 4 forwarders  to communicate with my indexer. I already executed add forward-server and set deploy-poll and created the outputs.conf from deployment-apps. On the forwader management, I can only see 3 instead of 4 forwarders available. I checked the _internal logs and got the following errors related to ShutdownHandler and TcpOutputProc and TcpOutputFd. Below are sample logs that I got:&lt;/P&gt;

&lt;P&gt;03-03-2020 13:19:44.312 -0500 INFO  ShutdownHandler - shutting down level "ShutdownLevel_ArchiveAndOneshot"&lt;BR /&gt;
host = xxx source = /opt/splunkforwarder/var/log/splunk/splunkd.logsourcetype = splunkd&lt;BR /&gt;
3/3/20&lt;BR /&gt;
1:19:44.312 PM&lt;BR /&gt;&lt;BR /&gt;
03-03-2020 13:19:44.312 -0500 INFO  ShutdownHandler - shutting down level "ShutdownLevel_SyslogOutput"&lt;BR /&gt;
host = xxx source = /opt/splunkforwarder/var/log/splunk/splunkd.logsourcetype = splunkd&lt;BR /&gt;
3/3/20&lt;BR /&gt;
1:19:44.312 PM&lt;BR /&gt;&lt;BR /&gt;
03-03-2020 13:19:44.312 -0500 INFO  TcpInputProc - TCP connection cleanup complete&lt;BR /&gt;
host = xxx source = /opt/splunkforwarder/var/log/splunk/splunkd.logsourcetype = splunkd&lt;BR /&gt;
3/3/20&lt;BR /&gt;
1:19:44.312 PM&lt;BR /&gt;&lt;BR /&gt;
03-03-2020 13:19:44.312 -0500 INFO  ShutdownHandler - shutting down level "ShutdownLevel_Scheduler"&lt;BR /&gt;
host = xxx source = /opt/splunkforwarder/var/log/splunk/splunkd.logsourcetype = splunkd &lt;/P&gt;

&lt;P&gt;3/2/20&lt;BR /&gt;
9:16:43.406 AM&lt;BR /&gt;&lt;BR /&gt;
03-02-2020 09:16:43.406 -0500 WARN  TcpOutputFd - Connect to xxx:9997 failed. Connection refused&lt;BR /&gt;
host = xxx source = /opt/splunkforwarder/var/log/splunk/splunkd.logsourcetype = splunkd&lt;BR /&gt;
3/2/20&lt;BR /&gt;
9:16:43.042 AM&lt;BR /&gt;&lt;BR /&gt;
03-02-2020 09:16:43.042 -0500 INFO  TcpOutputProc - Connection to xxx:9997 closed. Connection closed by server.&lt;BR /&gt;
host = xxx source = /opt/splunkforwarder/var/log/splunk/splunkd.logsourcetype = splunkd&lt;/P&gt;

&lt;P&gt;My guess is is being force to shutdon by the server or admin. Tho i am not sure. Does anyone experienced this? Any help is appreciated.&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 04:29:38 GMT</pubDate>
    <dc:creator>ptrckjncbngn</dc:creator>
    <dc:date>2020-09-30T04:29:38Z</dc:date>
    <item>
      <title>Splunk Forwarder ShutdownHandler</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-ShutdownHandler/m-p/487486#M83456</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have set up 4 forwarders  to communicate with my indexer. I already executed add forward-server and set deploy-poll and created the outputs.conf from deployment-apps. On the forwader management, I can only see 3 instead of 4 forwarders available. I checked the _internal logs and got the following errors related to ShutdownHandler and TcpOutputProc and TcpOutputFd. Below are sample logs that I got:&lt;/P&gt;

&lt;P&gt;03-03-2020 13:19:44.312 -0500 INFO  ShutdownHandler - shutting down level "ShutdownLevel_ArchiveAndOneshot"&lt;BR /&gt;
host = xxx source = /opt/splunkforwarder/var/log/splunk/splunkd.logsourcetype = splunkd&lt;BR /&gt;
3/3/20&lt;BR /&gt;
1:19:44.312 PM&lt;BR /&gt;&lt;BR /&gt;
03-03-2020 13:19:44.312 -0500 INFO  ShutdownHandler - shutting down level "ShutdownLevel_SyslogOutput"&lt;BR /&gt;
host = xxx source = /opt/splunkforwarder/var/log/splunk/splunkd.logsourcetype = splunkd&lt;BR /&gt;
3/3/20&lt;BR /&gt;
1:19:44.312 PM&lt;BR /&gt;&lt;BR /&gt;
03-03-2020 13:19:44.312 -0500 INFO  TcpInputProc - TCP connection cleanup complete&lt;BR /&gt;
host = xxx source = /opt/splunkforwarder/var/log/splunk/splunkd.logsourcetype = splunkd&lt;BR /&gt;
3/3/20&lt;BR /&gt;
1:19:44.312 PM&lt;BR /&gt;&lt;BR /&gt;
03-03-2020 13:19:44.312 -0500 INFO  ShutdownHandler - shutting down level "ShutdownLevel_Scheduler"&lt;BR /&gt;
host = xxx source = /opt/splunkforwarder/var/log/splunk/splunkd.logsourcetype = splunkd &lt;/P&gt;

&lt;P&gt;3/2/20&lt;BR /&gt;
9:16:43.406 AM&lt;BR /&gt;&lt;BR /&gt;
03-02-2020 09:16:43.406 -0500 WARN  TcpOutputFd - Connect to xxx:9997 failed. Connection refused&lt;BR /&gt;
host = xxx source = /opt/splunkforwarder/var/log/splunk/splunkd.logsourcetype = splunkd&lt;BR /&gt;
3/2/20&lt;BR /&gt;
9:16:43.042 AM&lt;BR /&gt;&lt;BR /&gt;
03-02-2020 09:16:43.042 -0500 INFO  TcpOutputProc - Connection to xxx:9997 closed. Connection closed by server.&lt;BR /&gt;
host = xxx source = /opt/splunkforwarder/var/log/splunk/splunkd.logsourcetype = splunkd&lt;/P&gt;

&lt;P&gt;My guess is is being force to shutdon by the server or admin. Tho i am not sure. Does anyone experienced this? Any help is appreciated.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:29:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-ShutdownHandler/m-p/487486#M83456</guid>
      <dc:creator>ptrckjncbngn</dc:creator>
      <dc:date>2020-09-30T04:29:38Z</dc:date>
    </item>
  </channel>
</rss>

