Knowledge Management

Important fix for 9.1.4/9.2.1

hrawat_splunk
Splunk Employee
Splunk Employee

https://docs.splunk.com/Documentation/Splunk/9.2.1/ReleaseNotes/Fixedissues
https://docs.splunk.com/Documentation/Splunk/9.1.4/ReleaseNotes/Fixedissues

One  customer reported a very interesting issue with graceful splunk restart.

Event missing during a graceful restart/rolling restart(splunk stop gracefully finished). useACK=true is an option but that ideally must be applied if splunk stop timed-out. This has been an issue for so many years.

This is important where config changes are pushed frequently, thus triggering frequent indexer/HF/IF restart.

The issue is fixed by 9.1.4/9.2.1

 

TcpInputProcessor not able to drain splunktcpin queue during graceful shutdown

 

How to detect if it's applicable for your deployment?
Check splunkd.log for 

WARN  TcpInputProc - Could not process data received from network. Aborting due to shutdown


Also from metrics.log see
https://community.splunk.com/t5/Knowledge-Management/During-indexer-restart-indexer-cluster-rolling-...

Labels (1)
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...