Getting Data In

Forwarder restarting every 10 minutes

jihape
Path Finder

Hi,

I have a dozen of UFs that are restarting every ten minutes. They are on Windows. Running 7.2 (latest supported version).

What I have checked so far:

- Splunk excluded from antivirus
- disabled deploymentclient
- UF running as local system

Any ideas what could trigger a restart after disabling deploymentclient.conf?

 

Labels (1)
0 Karma
1 Solution

jihape
Path Finder

Figured it out. Added some extra monitoring and found the server owner had a script that restarted the UF if it uses more than x memory 😂

Why he came to me with a problem he created I don't know.

View solution in original post

0 Karma

jihape
Path Finder

Figured it out. Added some extra monitoring and found the server owner had a script that restarted the UF if it uses more than x memory 😂

Why he came to me with a problem he created I don't know.

0 Karma

nwuest
Path Finder

Hi @jihape,

Just a thought, is there a file called “crash.log” in the following folder:

/opt/splunkforwarder/var/log/splunk/ 

If not, is there anything that is popping up in splunkd.log in the same folder? 

Look forward to hearing from you!

V/R,
nwuest

0 Karma
Get Updates on the Splunk Community!

Devesh Logendran, Splunk, and the Singapore Cyber Conquest

At this year’s Splunk University, I had the privilege of chatting with Devesh Logendran, one of the winners in ...

There's No Place Like Chrome and the Splunk Platform

WATCH NOW!Malware. Risky Extensions. Data Exfiltration. End-users are increasingly reliant on browsers to ...

Customer Experience | Join the Customer Advisory Board!

Are you ready to take your Splunk journey to the next level? 🚀 We invite you to join our elite squad ...