Deployment Architecture

DeploymentClient - Unable to send handshake message to deployment server. Error status is: not_connected

karthikbalakris
Explorer

hi i am sure i am missing something silly but honestly could not identify why i am getting this error "DeploymentClient - Unable to send handshake message to deployment server. Error status is: not_connected"

  • here is my serverclass.conf :

LINUX FORWARDERS

[serverClass:all_linux_forwarder]
whitelist.0 = 172.23.175.*
stateOnClient=enabled
restartSplunkd = true

[serverClass:all_linux_forwarder:app:unix]
stateOnClient=enabled
restartSplunkd = true

  • Here is my deployment client:

[deployment-client]

[target-broker:deploymentServer]
targetUri = 192.168.169.59:8889

*8889 is the mgmt port in our environment.

i tried reload deployment-server, i restarted splunk and the forwarder several time.

can any one help me why i am seeing this issue?

Much thanks in advance

0 Karma

pero1234
Path Finder

OK, first backup and delete serverclass.conf on splunk server.

Go to Splunk Manager > Deployment > Deployment server > New (here create your all_linux_forwarder class) > Save

Restart linux forwarder.

0 Karma

pero1234
Path Finder

Go to deployment client server (linux forwarder) and try with telnet or nc connect to splunk server (eg. telnet 192.168.169.59 8889).

If you can't that means your port 8889 on splunk server is blocked or even not open.

0 Karma

karthikbalakris
Explorer

thanks for the answer... but i tried this many times and i was able to telnet to the server.

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...