Deployment Architecture

Slow/Unresponsive Deployment Server. Deployment Clients timing out.

hrawat
Splunk Employee
Splunk Employee

There are 503 errors and DC can't connect messages in splunkd.log on deployment client.

Labels (2)
0 Karma
1 Solution

hrawat
Splunk Employee
Splunk Employee

That is because with default DS configuration, DS has reached a saturation point of handling too many phone home checks. Here are the recommendations to increase DS scalability.

On the DS server.conf

[sslConfig]

sslServerSessionTimeout = 7200

[httpServer]

dedicatedIoThreads = 10

 

Set following config to 512.

In $SPLUNK_HOME/etc/splunk-launch.conf on DS.

SPLUNK_LISTEN_BACKLOG = 512

Note: Make sure linux net.core.somaxconn setting is more than SPLUNK_LISTEN_BACKLOG.

 

On DC side  server.conf

[sslConfig]

useSslClientSessionCache=true

Upgrade all DC to 7.1.3 and above to have configurable and higher default DC timeouts. Before 7.1.3 these are hardcoded 5 sec.

connect_timeout = <positive integer>

* Default: 60

send_timeout = <positive integer>

* Default: 60

recv_timeout = <positive integer>

* Default: 60

View solution in original post

0 Karma

hrawat
Splunk Employee
Splunk Employee

That is because with default DS configuration, DS has reached a saturation point of handling too many phone home checks. Here are the recommendations to increase DS scalability.

On the DS server.conf

[sslConfig]

sslServerSessionTimeout = 7200

[httpServer]

dedicatedIoThreads = 10

 

Set following config to 512.

In $SPLUNK_HOME/etc/splunk-launch.conf on DS.

SPLUNK_LISTEN_BACKLOG = 512

Note: Make sure linux net.core.somaxconn setting is more than SPLUNK_LISTEN_BACKLOG.

 

On DC side  server.conf

[sslConfig]

useSslClientSessionCache=true

Upgrade all DC to 7.1.3 and above to have configurable and higher default DC timeouts. Before 7.1.3 these are hardcoded 5 sec.

connect_timeout = <positive integer>

* Default: 60

send_timeout = <positive integer>

* Default: 60

recv_timeout = <positive integer>

* Default: 60

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...