Splunk Universal Forwarder 6.0 (build 182611) on Windows 2008 mostly
For some reason an error situation occurred yesterday causing some, not all, forwarders to stop forwarding data. Logging on to each server and manually restarting the forwarder fixes the issue. But, with 62 servers, can I do this from the searchhead instead? I have tried splunk reload deploy-server but that does not seem to be the trick (I thought it did restart the forwarder, but that maybe that is only if the conf-files are changed?)
Anyways - question is: Can I restart all my forwarders in one operation?
reload deploy-server only reloads the forwarder if there is a mismatch in the checksums generated by the configuration file bundles. There could be a more elegant approach to this, but try one of the following:
Create an empty app (using the GUI -> Apps -> Create new App) and place it in the deployment-apps folder. Assign it to a a server class used by all your forwarders and make sure you have Restart Splunkd ticked for the specifc app. Issue reload deploy-server
Use some kind of Windows mechanism (SCOM?) to restart the Splunkd service on all your forwarders