<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DMC ALert - Missing forwarder for zombie entry in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/DMC-ALert-Missing-forwarder-for-zombie-entry/m-p/498994#M85062</link>
    <description>&lt;P&gt;Hi afx,&lt;BR /&gt;
if this answer solved your problem (or helped to do), please accept and/or upvote it.&lt;BR /&gt;
Bye and see next time.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
    <pubDate>Wed, 09 Oct 2019 06:44:13 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2019-10-09T06:44:13Z</dc:date>
    <item>
      <title>DMC ALert - Missing forwarder for zombie entry</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DMC-ALert-Missing-forwarder-for-zombie-entry/m-p/498991#M85059</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
I am getting a DMC alert for a missing forwarder even though that one (at least by client name, but not UUID) exists.&lt;/P&gt;

&lt;P&gt;Backgroud story:&lt;BR /&gt;
Forwarder was deleted completely on source system (don't ask...).&lt;BR /&gt;
Re-Installed from scratch with same parameters (of course, still different UUID, but same client name) and slightly newer code version.&lt;BR /&gt;
Rebuilt the forwarders DB on the deployment server (Monitoring Console -&amp;gt; Settings -&amp;gt; Forwarder Monitoring Setup -&amp;gt; Rebuild forwarder assets).&lt;BR /&gt;
Still I get errors about the missing forwarder and it shows the old version number for the code.&lt;/P&gt;

&lt;P&gt;So where is this Zombie stored and how do I get rid of it?&lt;/P&gt;

&lt;P&gt;thx&lt;BR /&gt;
afx&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2019 11:10:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DMC-ALert-Missing-forwarder-for-zombie-entry/m-p/498991#M85059</guid>
      <dc:creator>afx</dc:creator>
      <dc:date>2019-10-08T11:10:24Z</dc:date>
    </item>
    <item>
      <title>Re: DMC ALert - Missing forwarder for zombie entry</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DMC-ALert-Missing-forwarder-for-zombie-entry/m-p/498992#M85060</link>
      <description>&lt;P&gt;Hi afx,&lt;BR /&gt;
did you tried to rebuild the lookup "dmc_forwarder_assets" [Settings -- Forwarder Monitoring Setup -- Rebuild Forwarder Assets].&lt;BR /&gt;
In this way you rebuild your lookup with only the UFs that are really sending logs in the last period (configurable).&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:24:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DMC-ALert-Missing-forwarder-for-zombie-entry/m-p/498992#M85060</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-09-30T02:24:44Z</dc:date>
    </item>
    <item>
      <title>Re: DMC ALert - Missing forwarder for zombie entry</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DMC-ALert-Missing-forwarder-for-zombie-entry/m-p/498993#M85061</link>
      <description>&lt;P&gt;Hi Guiseppe,&lt;BR /&gt;
yes, as described in my post.&lt;/P&gt;

&lt;P&gt;But, your post suddenly triggered my leaky memory. &lt;BR /&gt;
It is not the deployment server where these alerts are generated but the search head for various strange reasons (modifed DMC alert with some lookups that are only maintained on the search head that make the alert more informative). &lt;/P&gt;

&lt;P&gt;So once I did the DB refresh on the search head the world went quiet again.&lt;/P&gt;

&lt;P&gt;thx&lt;BR /&gt;
afx&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2019 12:16:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DMC-ALert-Missing-forwarder-for-zombie-entry/m-p/498993#M85061</guid>
      <dc:creator>afx</dc:creator>
      <dc:date>2019-10-08T12:16:51Z</dc:date>
    </item>
    <item>
      <title>Re: DMC ALert - Missing forwarder for zombie entry</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/DMC-ALert-Missing-forwarder-for-zombie-entry/m-p/498994#M85062</link>
      <description>&lt;P&gt;Hi afx,&lt;BR /&gt;
if this answer solved your problem (or helped to do), please accept and/or upvote it.&lt;BR /&gt;
Bye and see next time.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2019 06:44:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/DMC-ALert-Missing-forwarder-for-zombie-entry/m-p/498994#M85062</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2019-10-09T06:44:13Z</dc:date>
    </item>
  </channel>
</rss>

