Deployment Architecture

UF establishes connection to DS, then it resets connection and is not seen in DS

rafaelruales
Explorer

Hi,

Splunk noob here.

I cannot get a deployment client to show up in deployment server.

turned DEBUG on splunkd.log and can see that it communicates with the deployment server:

DEBUG DC:DeploymentClient - channel=deploymentServer/phoneHome/default Success sending phonehome to DS.

I have ran tcpdump on the client and it makes a tcp connection to DS, goes through the TLS handshake fine, and then 30 seconds later, client send a FIN and then RST to the deployment server.

I get this freaking thing all the time, which I have googled of course, and the provided answer is worthless:

https://community.splunk.com/t5/Monitoring-Splunk/What-does-this-error-message-mean-quot-something-n...

./splunk display deploy-client
Deployment Client is enabled.
This command [GET /services/messages/restart_required/] needs splunkd to be up, and splunkd is down.

 

Are these the normal splunk processes?

splunk 7682 1 0 12:47 ? 00:00:08 splunkd -p 8089 restart
splunk 7683 7682 0 12:47 ? 00:00:00 [splunkd pid=7682] splunkd -p 8089 restart [process-runner]

Any ideas?

@gcusello 

Labels (2)
0 Karma
1 Solution

rafaelruales
Explorer

The issue was related to inconsistencies in the files: /etc/hostname and /etc/hosts regarding the machine name, since the inputs.conf file in $SPLUNK_HOME/etc/system/local references a specific name, which was different from the one in the 2 files mentioned above.

View solution in original post

0 Karma

rafaelruales
Explorer

The issue was related to inconsistencies in the files: /etc/hostname and /etc/hosts regarding the machine name, since the inputs.conf file in $SPLUNK_HOME/etc/system/local references a specific name, which was different from the one in the 2 files mentioned above.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...