For some reason an error situation occurred yesterday causing some, not all, forwarders to stop forwarding data. Logging on to each server and manually restarting the forwarder fixes the issue. But, with 62 servers, can I do this from the searchhead instead? I have tried splunk reload deploy-server
but that does not seem to be the trick (I thought it did restart the forwarder, but that maybe that is only if the conf-files are changed?)
Anyways - question is: Can I restart all my forwarders in one operation?
Hi Rune,
reload deploy-server only reloads the forwarder if there is a mismatch in the checksums generated by the configuration file bundles. There could be a more elegant approach to this, but try one of the following:
Hi Rune,
reload deploy-server only reloads the forwarder if there is a mismatch in the checksums generated by the configuration file bundles. There could be a more elegant approach to this, but try one of the following:
The first suggestion worked for me. Used a vbscript to verify, see http://hellem.org/blog/index.php/2014/04/01/how-to-get-uptime-for?blog=6