How to troubleshoot SC4S env_file corruption?


Hello all,

So I need help with a file corruption issue on my SC4S servers. I've had 2 SC4S servers running for several months with no issues.  Recently the contents in the /opt/sc4s/env_file has mysteriously changed that caused both SC4S servers to stop forwarding traffic, at different times.  My Linux admin confirmed no one manually changed the file, so I can't figure out how this is happening.  Has this happened to anyone else and if so how did you identify and fix the problem?

Thank you all in advance.

Labels (1)
0 Karma
Get Updates on the Splunk Community!

There's No Place Like Chrome and the Splunk Platform

Watch On DemandMalware. Risky Extensions. Data Exfiltration. End-users are increasingly reliant on browsers to ...

The Great Resilience Quest: 5th Leaderboard Update

The fifth leaderboard update for The Great Resilience Quest is out >> 🏆 Check out the ...

Devesh Logendran, Splunk, and the Singapore Cyber Conquest

At this year’s Splunk University, I had the privilege of chatting with Devesh Logendran, one of the winners in ...