Deployment Architecture

WARN DeploymentClient - DeploymentClient has been asked to redo-handshake. Resetting to initial state.

bigtyma
Communicator

I am seeing this error happen frequently in our configuration with multiple DeploymentServers. Can anyone tell me what this mean, and maybe why it is happening?
Thank you!

1 Solution

dwaddle
SplunkTrust
SplunkTrust

This is normally nothing to worry about - what it usually means is you've just a splunk reload deploy-server on your deployment server and clients are checking in and noticing that fact. There were some bugs in 5.0.2 around deployment server checkins. If you are running 5.0.2 for your deployment server, upgrade ASAP.

View solution in original post

0 Karma

dwaddle
SplunkTrust
SplunkTrust

This is normally nothing to worry about - what it usually means is you've just a splunk reload deploy-server on your deployment server and clients are checking in and noticing that fact. There were some bugs in 5.0.2 around deployment server checkins. If you are running 5.0.2 for your deployment server, upgrade ASAP.

0 Karma

dwaddle
SplunkTrust
SplunkTrust

This message is a prelude to the possibility restart, but is not always going to lead to one. When you issue the reload deploy-server then that causes forwarders to look for new versions of deployed apps and redeploy if needed. If an app is defined as restartSplunkd=true in serverclass.conf then when that app is updated and forwarders that have it installed will restart.

0 Karma

bigtyma
Communicator

I was concered since it appeared to he happening every few minutes causing restarts on all of the UF's it appears to have settled down at this point.

0 Karma

bigtyma
Communicator

Thank you for the response!

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...