I am running an instance of Splunk as a heavy weight forwarder on a RHES fail-over cluster. When the cluster detects that splunk is not running it tries to detach the storage and reconnect to another node and restart the splunkd on the new node. Unfortunately the estreamer.py process is not shutting down so the system can not close the connection to the SAN. I can modify the init script to detect and kill the Estreamer process but I would like to ask if anyone else is having a similar problem and has a better solution.
↧