Hello. I noticed on a U/F, "Splunk destroying TcpOutputClient during shutdown/reload" as a level INFO and happens 4 or 5 times a minute for each of the 3 indexers.
The U/F has been running for quite some time and is not in a shutdown/reload situation and I am receiving events both _internal and OS data from the TA_Splunk_nix from it.
Is destroying a connection a normal message and what would cause that? I can't seem to find anything online about this message.
Please take a look. Is it related to the same?
Fixed issues - Splunk Documentation
Slow indexer/receiver detection capability - Splunk Community
Splunk crash during tcpout (outputs.conf) reload - Splunk Community
Please take a look. Is it related to the same?
Fixed issues - Splunk Documentation
Slow indexer/receiver detection capability - Splunk Community
Splunk crash during tcpout (outputs.conf) reload - Splunk Community
Looking through the 2nd article that you suggested, it was noticed that the outputs.conf had
autoLBFrequency = 15
forceTimebasedAutoLB = true
Removed forceTimebasedAutoLB = true and the message stopped after the U/F restarted. It appears that the 2 entries were conflicting with each other.
Thank you for the guidance!