Getting Data In

Forwarder restarting every 10 minutes

Path Finder

Hi,

I have a dozen of UFs that are restarting every ten minutes. They are on Windows. Running 7.2 (latest supported version).

What I have checked so far:

- Splunk excluded from antivirus
- disabled deploymentclient
- UF running as local system

Any ideas what could trigger a restart after disabling deploymentclient.conf?

 

Labels (1)
0 Karma
1 Solution

Path Finder

Figured it out. Added some extra monitoring and found the server owner had a script that restarted the UF if it uses more than x memory 😂

Why he came to me with a problem he created I don't know.

View solution in original post

0 Karma

Path Finder

Figured it out. Added some extra monitoring and found the server owner had a script that restarted the UF if it uses more than x memory 😂

Why he came to me with a problem he created I don't know.

View solution in original post

0 Karma

Path Finder

Hi @jihape,

Just a thought, is there a file called “crash.log” in the following folder:

/opt/splunkforwarder/var/log/splunk/ 

If not, is there anything that is popping up in splunkd.log in the same folder? 

Look forward to hearing from you!

V/R,
nwuest

0 Karma
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes
and swag!