Closed brattonc closed 9 years ago
I've been using this set of changes for a couple weeks now and I haven't experienced any issues with lost events since. And while this doesn't fix the root cause of the issue, a race condition still exists, the additional 1-2 seconds that watching the windows service provides is enough to prevent data loss in the vast majority of situations.
This set of changes is a stopgap attempt to fix some of the issues around graceful shutdown of modular inputs when Splunk itself is shutting down. See this issue for details.
This change attempts to avoid the issue of lost events by: