Monitoring Splunk

Why is there universalforwarder 8.1.3 aix disconnected error?

haruban36
Explorer

Splunk Enterprise 8.1.3
I installed splunkforwarder-8.1.3-63079c59e632-AIX-powerpc.

There was a problem with the universalforwarder connection being disconnected, so I restarted it.
However, even after restarting, the connection was lost after a certain period of time.

I am attaching the last 15 lines of splunkd log before disconnection.
Check the logs below for further confirmation.


=============================================================================== 
03-29-2023 05:00:28.918 +0900 INFO WatchedFile - Will begin reading at offset=338882 for file='/IBTRANS/SPQ/var/log/event_log'.
03-29-2023 05:00:28.919 +0900 INFO TcpOutputProc - _isHttpOutConfigured=NOT_CONFIGURED
03-29-2023 05:00:28.922 +0900 INFO TcpOutputProc - Connected to idx=150.1.13.90:9997, pset=0, reuse=0.
03-29-2023 05:00:28.927 +0900 INFO loader - Limiting REST HTTP server to 400000 sockets
03-29-2023 05:00:28.927 +0900 INFO loader - Limiting REST HTTP server to 10922 threads
03-29-2023 05:00:28.927 +0900 WARN X509Verify - X509 certificate (O=SplunkUser,CN=SplunkServerDefaultCert) should not be used, as it is issued by Splunk's own default Certificate Authority (CA). This puts your Splunk instance at very high-risk of the MITM attack. Either commercial-CA-signed or self-CA-signed certificates must be used; see: <http://docs.splunk.com/Documentation/Splunk/latest/Security/Howtoself-signcertificates>
03-29-2023 05:00:28.938 +0900 INFO ArchiveProcessor - Handling file=/LOG/tux/CLOG.032723.Z
03-29-2023 05:00:28.942 +0900 INFO ArchiveProcessor - reading path=/LOG/tux/CLOG.032723.Z (seek=0 len=113564693)
03-29-2023 05:00:29.027 +0900 INFO UiHttpListener - Web UI disabled in web.conf [settings]; not starting
03-29-2023 05:00:29.097 +0900 INFO WatchedFile - Will begin reading at offset=13491182 for file='/LOG/tux/CLOG.032923'.
03-29-2023 05:00:29.250 +0900 ERROR ProcessRunner - child's last words: cannot find portable_pid_t 9372426 in _pidToUniqMap
03-29-2023 05:00:29.252 +0900 FATAL ProcessRunner - Unexpected EOF from process runner child!
03-29-2023 05:00:29.299 +0900 ERROR ProcessRunner - helper process seems to have died (child exited with code 255)!
03-29-2023 05:00:29.299 +0900 ERROR ExecProcessor - Exception attempting to setup event loop
03-29-2023 05:00:29.299 +0900 ERROR ExecProcessor - child's last words: cannot find portable_pid_t 9372426 in _pidToUniqMap

Labels (3)
0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...