Getting Data In

Forwarder restarting every 10 minutes

jihape
Path Finder

Hi,

I have a dozen of UFs that are restarting every ten minutes. They are on Windows. Running 7.2 (latest supported version).

What I have checked so far:

- Splunk excluded from antivirus
- disabled deploymentclient
- UF running as local system

Any ideas what could trigger a restart after disabling deploymentclient.conf?

 

Labels (1)
0 Karma
1 Solution

jihape
Path Finder

Figured it out. Added some extra monitoring and found the server owner had a script that restarted the UF if it uses more than x memory 😂

Why he came to me with a problem he created I don't know.

View solution in original post

0 Karma

jihape
Path Finder

Figured it out. Added some extra monitoring and found the server owner had a script that restarted the UF if it uses more than x memory 😂

Why he came to me with a problem he created I don't know.

0 Karma

nwuest
Path Finder

Hi @jihape,

Just a thought, is there a file called “crash.log” in the following folder:

/opt/splunkforwarder/var/log/splunk/ 

If not, is there anything that is popping up in splunkd.log in the same folder? 

Look forward to hearing from you!

V/R,
nwuest

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...