Monitoring Splunk

Why is there a slowness in the restart of Spunk components?

vinod50rao
New Member

Hi Team,

I'm seeing slowness in the restart of Splunk components. All my Forwarders, indexers and search heads are on Linux OS. I'm making Forwarders first down than indexers and in last search heads,

We are seeing restart latency with Forwarders, in the meantime i'm directly shutting down the machine not stopping any service first. will that make change. Please provide your expert comments.

Thanks!
Vinod Yadav.

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Depending on what the forwarder is doing, it can take some time to stop/restart. This is typically due to currently active file monitors and modular inputs running. The forwarder will try and clear the queues before it restarts, meaning it will try and wait till and EOF / end of event before stopping the splunkd process. Similar is true on indexers, they will try and wait till search jobs have completed and indexing queues have emptied.

0 Karma

adonio
Ultra Champion

can you elaborate?
what is the reason for frequent restarts? can you see the console while restarting? any messages during restart?
how do you measure the slowness? how long does a forwarder restart takes? indexer? search head?

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...