All Apps and Add-ons

Why does the Splunk Add-on for EMC VNX collect data only once after a reboot and some data is missing?

dkoops
Path Finder

I configured the Splunk Add-on for EMC VNX and after a reboot, it collects data, but only once and not everything. It's like the script crashes or something. After a reboot, I get a bit of data again, and again a random amount. Tried reinstalling the add-on, reconfiguring, etc. Nothing seems to help. Logfile doesn't give me much:

2015-10-19 11:39:05,927 INFO 4744 - start collect pool device perf for xxx.xxx.xxx.xxx
2015-10-19 11:39:06,802 INFO 4744 - end collect pool device perf for xxx.xxx.xxx.xxx

Already opened a ticket at support, but maybe this leads to a quicker solution.

0 Karma

matt4321
Explorer

Can you post more details like the last few items in the ta_vnx.log (in "\program files\splunk\var\log\splunk\") to see if there is anything helpful in it? I find the above link is written exactly for Windows as well as linux. I had issues at first and then checked the logs and found that I was missing some items in the inputs.conf for the app. How often do you have your ta_vnx_collection.conf?

0 Karma

dkoops
Path Finder

The last part of the logging is below; looks kinda normal to me. It just appears to be running but nothing gets into Splunk. Except for the first several random events after a restart. The ta_vnx_collection.conf was at default at first (60 and 360) but I tried it with a 10 times longer interval as well (600 and 3600).

2015-10-26 13:31:46,257 INFO 7240 - Start vnx_data_loader://xxx. Metric=vnx_block_performance
2015-10-26 13:31:46,257 INFO 7240 - start collect sp perf for XXX.XXX.XXX.XX
2015-10-26 13:31:47,398 INFO 7240 - end collect sp perf for XXX.XXX.XXX.XX
2015-10-26 13:31:47,398 INFO 7240 - start collect drive perf for XXX.XXX.XXX.XX
2015-10-26 13:31:47,757 INFO 7240 - end collect drive perf for XXX.XXX.XXX.XX
2015-10-26 13:31:47,757 INFO 7240 - start collect rg device perf for XXX.XXX.XXX.XX
2015-10-26 13:31:48,101 INFO 7240 - end collect rg device perf for XXX.XXX.XXX.XX
2015-10-26 13:31:48,101 INFO 7240 - start collect pool device perf for XXX.XXX.XXX.XX
2015-10-26 13:31:48,664 INFO 7240 - end collect pool device perf for XXX.XXX.XXX.XX
2015-10-26 13:31:48,664 INFO 7240 - End vnx_data_loader://xxx. Metric=vnx_block_performance
2015-10-26 13:31:49,289 INFO 9716 - Start vnx_data_loader://xxx. Metric=vnx_block_performance
2015-10-26 13:31:49,289 INFO 9716 - start collect sp perf for XXX.XXX.XXX.XX1
2015-10-26 13:31:50,632 INFO 9716 - end collect sp perf for XXX.XXX.XXX.XX1
2015-10-26 13:31:50,632 INFO 9716 - start collect drive perf for XXX.XXX.XXX.XX1
2015-10-26 13:31:50,993 INFO 9716 - end collect drive perf for XXX.XXX.XXX.XX1
2015-10-26 13:31:50,993 INFO 9716 - start collect rg device perf for XXX.XXX.XXX.XX1
2015-10-26 13:31:51,414 INFO 9716 - end collect rg device perf for XXX.XXX.XXX.XX1
2015-10-26 13:31:51,414 INFO 9716 - start collect pool device perf for XXX.XXX.XXX.XX1
2015-10-26 13:31:52,071 INFO 9716 - end collect pool device perf for XXX.XXX.XXX.XX1
2015-10-26 13:31:52,071 INFO 9716 - End vnx_data_loader://xxx. Metric=vnx_block_performance
0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee
0 Karma

dkoops
Path Finder

Well the app runs on a windows machine so the largest part of the troubleshooting page seems non-applicable here. I did however reconfigure it several times, and reinstalled the app. Looks like the config part is ok since it starts normally after a restart but then just stops every time before finishing the first run. I have a feeling the underlying scripts just crash for some reason and then don't start again.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...