Getting Data In

Forwarder restarting every 10 minutes

jihape
Path Finder

Hi,

I have a dozen of UFs that are restarting every ten minutes. They are on Windows. Running 7.2 (latest supported version).

What I have checked so far:

- Splunk excluded from antivirus
- disabled deploymentclient
- UF running as local system

Any ideas what could trigger a restart after disabling deploymentclient.conf?

 

Labels (1)
0 Karma
1 Solution

jihape
Path Finder

Figured it out. Added some extra monitoring and found the server owner had a script that restarted the UF if it uses more than x memory 😂

Why he came to me with a problem he created I don't know.

View solution in original post

0 Karma

jihape
Path Finder

Figured it out. Added some extra monitoring and found the server owner had a script that restarted the UF if it uses more than x memory 😂

Why he came to me with a problem he created I don't know.

0 Karma

nwuest
Path Finder

Hi @jihape,

Just a thought, is there a file called “crash.log” in the following folder:

/opt/splunkforwarder/var/log/splunk/ 

If not, is there anything that is popping up in splunkd.log in the same folder? 

Look forward to hearing from you!

V/R,
nwuest

0 Karma
Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

New Release | Splunk Cloud Platform 10.1.2507

Hello Splunk Community!We are thrilled to announce the General Availability of Splunk Cloud Platform 10.1.2507 ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...