Deployment Architecture

How can I restart all my forwarders?

rune_hellem
Contributor
  • Splunk 6.0.1 (build 189883) on Windows 2012
  • Splunk Universal Forwarder 6.0 (build 182611) on Windows 2008 mostly

For some reason an error situation occurred yesterday causing some, not all, forwarders to stop forwarding data. Logging on to each server and manually restarting the forwarder fixes the issue. But, with 62 servers, can I do this from the searchhead instead? I have tried splunk reload deploy-server but that does not seem to be the trick (I thought it did restart the forwarder, but that maybe that is only if the conf-files are changed?)

Anyways - question is: Can I restart all my forwarders in one operation?

Tags (2)
0 Karma
1 Solution

mikaelbje
Motivator

Hi Rune,

reload deploy-server only reloads the forwarder if there is a mismatch in the checksums generated by the configuration file bundles. There could be a more elegant approach to this, but try one of the following:

  1. Create an empty app (using the GUI -> Apps -> Create new App) and place it in the deployment-apps folder. Assign it to a a server class used by all your forwarders and make sure you have Restart Splunkd ticked for the specifc app. Issue reload deploy-server
  2. Use some kind of Windows mechanism (SCOM?) to restart the Splunkd service on all your forwarders

View solution in original post

mikaelbje
Motivator

Hi Rune,

reload deploy-server only reloads the forwarder if there is a mismatch in the checksums generated by the configuration file bundles. There could be a more elegant approach to this, but try one of the following:

  1. Create an empty app (using the GUI -> Apps -> Create new App) and place it in the deployment-apps folder. Assign it to a a server class used by all your forwarders and make sure you have Restart Splunkd ticked for the specifc app. Issue reload deploy-server
  2. Use some kind of Windows mechanism (SCOM?) to restart the Splunkd service on all your forwarders

rune_hellem
Contributor

The first suggestion worked for me. Used a vbscript to verify, see http://hellem.org/blog/index.php/2014/04/01/how-to-get-uptime-for?blog=6

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...