Deployment Architecture

What is the deployment polling data meaning for ?

sunrise
Contributor

Hi splunkers,

Yesterday, I was monitoring the splunk_access.log and found the log messages
that deployment clients poll to the deployment server, both platforms are Windows Server, Splunk V5.

The messages in one poll are below.

172.XX.XX.XXX - - [29/Oct/2013:02:56:31.939 +0900] "POST /services/broker/phonehome/connection_172.XX.XX.XXX_8089_splk23_splk23_41EB9A91-5859-4029-A6FE-D7C46CDEB486 HTTP/1.0" 200 278 - - - 219ms
172.XX.XX.XXX - - [29/Oct/2013:02:56:31.721 +0900] "POST /services/broker/phonehome/connection_172.XX.XX.XXX_8089_splk23_splk23_41EB9A91-5859-4029-A6FE-D7C46CDEB486 HTTP/1.0" 200 995 - - - 219ms

Now I have a question that what each messages which have different bytes are meaning for ?
And I also found that sometimes 995 bytes data got lost, or not the normal interval.
Is it a problem, or not ?

Thank you for your help.

Tags (2)
0 Karma
1 Solution

yannK
Splunk Employee
Splunk Employee

This is the phonehome call from the deployment-clients calling the deployment-server.
They report with their IP, hostname, the clientname and GUID for the matching with the serverclass.conf.

Each client tries to connect after the phonehome interval modulo some random seconds.
i do not know why the bytes change.

View solution in original post

yannK
Splunk Employee
Splunk Employee

This is the phonehome call from the deployment-clients calling the deployment-server.
They report with their IP, hostname, the clientname and GUID for the matching with the serverclass.conf.

Each client tries to connect after the phonehome interval modulo some random seconds.
i do not know why the bytes change.

yannK
Splunk Employee
Splunk Employee

on 6.0 the clients are not using strictly the "phoneHomeIntervalInSecs", they add some randomness to it avoid peaks of connections.

0 Karma

sunrise
Contributor

Thank you, yannK.
So you think that phonehome call is based on the attributes "phoneHomeIntervalInSecs" in deploymentclient.conf,
but client connections from clients to server are slightly late.

Universal Forwarders in Windows Server post two kinds of bytes like above log, but in Linux don't do that...

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...