Getting Data In

How does the deployment client decide which ipv4 address (of possibly multiple) to present when phoning home?

dstaulcu
Builder

The other day I came across universal forwarder based deployment client which was not receiving deployment server apps as expected.

When looking at the HttpPubSubConnection (PhoneHome) records in the splunkd log on the deployment client I noticed that the IP address posted to the deployment server was an IP address of one of the host's network interfaces which did not have a route to the deployment server. When I restarted the splunk agent, the next phone home happened to post the correct IPv4 address having a valid route to the deployment server, and of course the apps downloaded.

How does the deployment client decide which ipv4 address (of possibly multiple) to present when phoning home?

2018-01-24: Initial submission
2018-12-09: bump1

0 Karma

rfaircloth_splu
Splunk Employee
Splunk Employee

The client IP is based on what the tcp layer of the server sees, it could be the NAT or proxy address instead of the actual client ip.

0 Karma

harsmarvania57
Ultra Champion

Hi,

To best of my knowledge it's based on Routing table present on OS.

For example: You have 2 interface eth0 and eth1, eth0 does not have route to Deployment Server on Switch/Firewall & eth1 has route present to pass traffic to Deployment Server and default route passing traffic from eth0 on OS and Deployment Server does not belong to eth0 or eth1 subnet.

In this case Forwarder will not able to fetch apps from Deployment Server because it will initiate connection from Forwarder to Deployment Server on default route which is eth0 and that subnet does not have route present to Deployment Server.

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...