Hi,
I've set up a Unix universal forwarder to monitor text-based files on a system.
I always thought forwarders have a small footprint, but my forwarder currently eats up 17% of the CPU of the machine it's installed on.
I checked everything and found something weird.
Splunkd_access.log writes approx. 2 MB of data every second. Splunkd_access.log rolls about every two minutes.
Splunk-Forwarder-Version: 6.4.1
Splunkd_access.log shows the following constant output:
-somedate- "POST /services/shcluster/member/consensus/pseudoid/raft_request_vote?output_mode=json HTTP/1.1" 401 71 - - - 0ms
-somedate- "POST /services/shcluster/member/consensus/pseudoid/raft_request_vote?output_mode=json HTTP/1.1" 401 71 - - - 0ms
-somedate- "POST /services/shcluster/member/consensus/pseudoid/raft_request_vote?output_mode=json HTTP/1.1" 401 71 - - - 0ms
-somedate- "POST /services/shcluster/member/consensus/pseudoid/raft_request_vote?output_mode=json HTTP/1.1" 401 71 - - - 0ms
-somedate- "POST /services/shcluster/member/consensus/pseudoid/raft_request_vote?output_mode=json HTTP/1.1" 401 71 - - - 0ms
-somedate- "POST /services/shcluster/member/consensus/pseudoid/raft_request_vote?output_mode=json HTTP/1.1" 401 71 - - - 0ms
-somedate- "POST /services/shcluster/member/consensus/pseudoid/raft_request_vote?output_mode=json HTTP/1.1" 401 71 - - - 0ms
-somedate- "POST /services/shcluster/member/consensus/pseudoid/raft_request_vote?output_mode=json HTTP/1.1" 401 71 - - - 0ms
-somedate- "POST /services/shcluster/member/consensus/pseudoid/raft_request_vote?output_mode=json HTTP/1.1" 401 71 - - - 0ms
-somedate- "POST /services/shcluster/member/consensus/pseudoid/raft_request_vote?output_mode=json HTTP/1.1" 401 71 - - - 0ms
While splunkd.log throws me this repeatedly:
-somedate- INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/splunkforwarder/var/log/splunk/splunkd_access.log'.
-somedate- INFO WatchedFile - Will begin reading at offset=0 for file='/opt/splunkforwarder/var/log/splunk/splunkd_access.log'.
----------
Anyone here who has seen this strange behavior before?
Thanks in advance!
Best regards,
pyro_wood
↧