<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: UF not in CMC in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/UF-not-in-CMC/m-p/746350#M118624</link>
    <description>The rebuild of forwarders assets should happen automatically with period what is defined into CMC -&amp;gt; Forwarders -&amp;gt; Forwarder Monitoring Setup: Data Collection Interval.&lt;BR /&gt;If that time has gone after you have add this UF and you can see those logs in _internal index and this continue I propose that you create a support ticket that they could figure out why this forwarder asset hasn't updated as expected.&lt;BR /&gt;&lt;BR /&gt;Of course if time has elapsed less than that period you could update it manually or decrease that time and build it again. What is preferred time period for update is depending on your needs to get those UF into this list and how many UFs you have.</description>
    <pubDate>Fri, 16 May 2025 16:58:55 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2025-05-16T16:58:55Z</dc:date>
    <item>
      <title>UF not in CMC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/UF-not-in-CMC/m-p/745745#M118524</link>
      <description>&lt;P&gt;&lt;EM&gt;&lt;BR /&gt;Newly installed Universal forwarders on windows servers are forwarding logs to Splunk Cloud but newly installed forwarders name is not coming up in forwarders list in Cloud Monitoring Console. What could be the reason?&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 May 2025 05:16:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/UF-not-in-CMC/m-p/745745#M118524</guid>
      <dc:creator>msatish</dc:creator>
      <dc:date>2025-05-08T05:16:41Z</dc:date>
    </item>
    <item>
      <title>Re: UF not in CMC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/UF-not-in-CMC/m-p/745747#M118525</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/275655"&gt;@msatish&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You need to rebuild the forwarder asset table in the CMC for it to update properly.&lt;/P&gt;&lt;P&gt;Go to CMC &amp;gt; Forwarders &amp;gt; Forwarder Monitoring Setup &amp;gt; Rebuild Forwarder Assets&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiran_panchavat_0-1746684249585.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/38904iA82850857234FAEB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kiran_panchavat_0-1746684249585.png" alt="kiran_panchavat_0-1746684249585.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Refer the below docs:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/9.3.2411/Admin/MonitoringForwarders" target="_blank" rel="noopener"&gt;Use&amp;nbsp;the Forwarder dashboards - Splunk Documentation&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/monitoring-console-triggered-alerts-missing-forwarders-but-they/m-p/458517" target="_blank"&gt;Solved: monitoring console triggered alerts - missing forw... - Splunk Community&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Why-is-our-universal-forwarder-not-visible-in-the-Forwarder/m-p/441153" target="_blank"&gt;Solved: Why is our universal forwarder not visible in the ... - Splunk Community&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 May 2025 06:20:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/UF-not-in-CMC/m-p/745747#M118525</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-05-08T06:20:45Z</dc:date>
    </item>
    <item>
      <title>Re: UF not in CMC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/UF-not-in-CMC/m-p/745761#M118527</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/275655"&gt;@msatish&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It looks like you need to "&lt;SPAN&gt;Rebuild Forwarder Assets". This can be done by&amp;nbsp;going to&amp;nbsp;&lt;STRONG&gt;Cloud Monitoring Console &amp;gt; Forwarders &amp;gt; Forwarder Monitoring Setup&lt;/STRONG&gt;. and clicking on the "Rebuild Forwarder Assets" button.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I'd also recommend checking out the&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/9.3.2408/Admin/MonitoringForwarders#:~:text=gz%C2%A0lookup%20file.-,Review%20the%20Forwarder%20Monitoring%20Setup%20page,-To%20investigate%20this" target="_self"&gt;Review the Forwarder Monitoring Setup page docs&lt;/A&gt; which has more info about this and how to view/manage your forwarders via the CMC.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Thu, 08 May 2025 07:58:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/UF-not-in-CMC/m-p/745761#M118527</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-05-08T07:58:48Z</dc:date>
    </item>
    <item>
      <title>Re: UF not in CMC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/UF-not-in-CMC/m-p/746350#M118624</link>
      <description>The rebuild of forwarders assets should happen automatically with period what is defined into CMC -&amp;gt; Forwarders -&amp;gt; Forwarder Monitoring Setup: Data Collection Interval.&lt;BR /&gt;If that time has gone after you have add this UF and you can see those logs in _internal index and this continue I propose that you create a support ticket that they could figure out why this forwarder asset hasn't updated as expected.&lt;BR /&gt;&lt;BR /&gt;Of course if time has elapsed less than that period you could update it manually or decrease that time and build it again. What is preferred time period for update is depending on your needs to get those UF into this list and how many UFs you have.</description>
      <pubDate>Fri, 16 May 2025 16:58:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/UF-not-in-CMC/m-p/746350#M118624</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-05-16T16:58:55Z</dc:date>
    </item>
    <item>
      <title>Re: UF not in CMC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/UF-not-in-CMC/m-p/746358#M118628</link>
      <description>&lt;P&gt;While rebuilding forwarder database might sometimes help if it becomes corrupted or contains too many orphaned entries, the question worth looking into is how your UFs are deployed and configured. Are you sure they aren't sharing the GUID and hostname?&lt;/P&gt;</description>
      <pubDate>Fri, 16 May 2025 18:35:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/UF-not-in-CMC/m-p/746358#M118628</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-05-16T18:35:36Z</dc:date>
    </item>
  </channel>
</rss>

