Deployment Architecture

Universal Forwarder Unable to Download Apps from Deployment Server

dannyrm
Engager

Hi all,

I'm having some issues onboarding some new server logs into Splunk. These servers are RedHat 6 and 7 machines. I've gotten the Universal Forwarder agent installed onto them and dropped my depolyment_client app into /opt/splunkforwarder/etc/apps directory (app has a deploymentclient.conf file in it). These servers connect to my DS fine, but then encounter an issue when trying to download the other two apps that are a part of some different serverclasses (one app is the splunk TA for linux and the other is an app that points to my indexers). 

I saw on the splunkd log file on one of the machines I was getting this error:

-0500 WARN HTTPClient [18097 HttpClientPollingThread_DD738BE1-8B55-41C7-B82B-A9348CA4DF30] - Download of file /opt/splunkforwarder/var/run/all_nix_hosts/nix_forwarder_outputs_ssl-1630327417.bundle failed with status 502

I have other Linux machines that have connected to the DS and recieved the apps perfectly fine and are sending data. I've also done Windows servers with their respective apps and no issues there. Any idea why this may be happening? 
Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @dannyrm,

it's very difficoult to debug a problem like this by messages!

Anyway, let me understand:

  • you have many Linux servers,
  • you deployed apps in all of them using a DS,
  • in few of these servers you have an error deploying apps,
  • but not all the apps, only two of them that are correctly deployed on other Linux servers,

is it correct?

Some question:

  • did you checked the space on filesystem on these machines?
  • Is the user running Splunk the same in all machines?
  • Is there something different in only these machines than the other Linux machines?

Ciao.

Giuseppe

0 Karma

isoutamo
SplunkTrust
SplunkTrust

One additional questions over @gcusello 's 

Should there be a proxy between those UF and DS?

r. Ismo

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...