Splunk AppDynamics

Configurations deleted after Machine agent went down.

Amith_B
Engager

The configurations which was done in service availability module were deleted after the Machine agent went down(url monitoring was done from this machine agent). How it can be recovered now?. There were almost 200 URL being configured in the server through controller(not from yml file).

Labels (3)

Brian_Homrich
Engager

Amith.B,

I'm working with another environment that saw the same behavior.  In our case we were permanently moving the MachineAgent previously supporting the SAM checks to another Controller,  and after the node was removed (we saw it deleted in the on-prem audit log),   the SAM check was removed as well.

It may be tied to the fact that you can't create a SAM check configuration without having a node to run it.

Unfortunately,  the SAM configuration appears to be removed from the controller DB as well,  as the table in the on-prem controller database was empty.     In our case the number of checks was small (approximately a dozen).

We're moving forward planning two approaches to workaround this:   

  1. use the ConfigExporter to backup the SAM checks once they're recreated.
  2. put extra documentation into the environment wiki to make sure we don't delete that agent

It should be possible to put a HealthRule on the availability of that specific Agent and go critical quickly if it stops reporting.   I would cause that alert to warn and go critical aggressively to your NOC or Operations team managing the SAM configuration.

I say that because,  in our case:  looking at the controller audit log, it appeared the node was deleted after 2 days,  and that doesn't seem to match up with any of the node retention settings that were in effect in the controller (node.retention.period was 500,  node.permanent.deletion.period was 720,  so basically 20 days to mark the node,  and 30 to remove it)

Good Luck

Venkat_Parvath1
Explorer

Hi,

I am also noticing the same behavior on both Linux and windows based Machine Agent-based SAM configurations.  Were you able to find a cause for this  ?  bug or expected behavior?

Also,  I see that it took over 24 hrs for the config to vanish, what was your experience in duration?

thanks

Ven

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...