All Apps and Add-ons

Splunk App and Add-on for VMWare: Why have Data Collection Nodes (DCN) suddenly stopped working with error "apps are not there"?

HCadmins
Communicator

My Splunk DCN for VMware suddenly stopped sending data.

alt text

The apps are there

alt text

I have restarted the DCN and confirmed that the services are running. Any help would be appreciated!

0 Karma

Masa
Splunk Employee
Splunk Employee

Can you double-check and try the latest version in both DCN and SH VMware Scheduler? Especially SA-Utils should not be used for the latest version.

0 Karma

HCadmins
Communicator

How do I update the DCN? Do I need to delete and re-deploy it?

0 Karma

Masa
Splunk Employee
Splunk Employee

Probably that's best.
1. Stop Scheduler, delete the DCN node from the config page
2. Stop DCN Splunk
3. Remove all the VMware apps package
4. Deploy a new package
5. Start the DCN Splunk
6. Set up DCNs
7. Start Scheduler

0 Karma

HCadmins
Communicator

Can I just delete the virtual machine and download a new .ova for the DCN (for steps 2-5)?

0 Karma

HCadmins
Communicator

I deleted the DCN and redeployed it using a fresh OVA. I followed the instructions exactly. I am still getting the same error.

0 Karma

HCadmins
Communicator

Splunk DCN is currently at version 161229a

And, all apps seem to be there

alt text

0 Karma

Masa
Splunk Employee
Splunk Employee

Please file a Splunk Support case, and submit diags from the scheduler and DCN. I believe that's faster route to identify cause of the issue.

0 Karma

HCadmins
Communicator

Does anyone have any advice on this?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...