<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How does Cluster Manager populate dmc_forwarder_assets input lookup csv table? in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/How-does-Cluster-Manager-populate-dmc-forwarder-assets-input/m-p/696710#M10331</link>
    <description>&lt;P&gt;The forwarder asset table is generated from tcpin_connections metrics in _internal.&amp;nbsp; FTR, this is done by the Monitoring Console (MC), not the Cluster Manager (CM).&amp;nbsp; The CM and MC can be co-located in limited conditions - see &lt;A href="https://docs.splunk.com/Documentation/Splunk/9.3.0/Indexer/Systemrequirements#Additional_roles_for_the_manager_node" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.3.0/Indexer/Systemrequirements#Additional_roles_for_the_manager_node&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;Seeing the same forwarder many times often happens when a host is cloned without first preparing the forwarder for cloning.&amp;nbsp; See the CLONEPREP installer option at &lt;A href="https://docs.splunk.com/Documentation/Forwarder/9.3.0/Forwarder/InstallaWindowsuniversalforwarderfromaninstaller" target="_blank"&gt;https://docs.splunk.com/Documentation/Forwarder/9.3.0/Forwarder/InstallaWindowsuniversalforwarderfromaninstaller&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;The fix is to delete the GUID on each server (using the &lt;FONT face="courier new,courier"&gt;splunk clone-prep-clear-config&lt;/FONT&gt; command) and then restart Splunk so it generates a new GUID.&amp;nbsp; Then have the Monitoring Console generate a new forwarder assets table.&lt;/P&gt;</description>
    <pubDate>Mon, 19 Aug 2024 12:16:49 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2024-08-19T12:16:49Z</dc:date>
    <item>
      <title>How does Cluster Manager populate dmc_forwarder_assets input lookup csv table?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-does-Cluster-Manager-populate-dmc-forwarder-assets-input/m-p/696445#M10326</link>
      <description>&lt;P&gt;Does anyone know how does Cluster Manager populate dmc_forwarder_assets input lookup csv table?&lt;/P&gt;&lt;P&gt;I have an issue where my UF forwarder reports show hosts with os containing repeated entries of Windows hundreds and even 000's of times.&lt;/P&gt;&lt;P&gt;I'd like to check how this data table is being populated by CM?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2024 03:16:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-does-Cluster-Manager-populate-dmc-forwarder-assets-input/m-p/696445#M10326</guid>
      <dc:creator>slider8p2023</dc:creator>
      <dc:date>2024-08-16T03:16:23Z</dc:date>
    </item>
    <item>
      <title>Re: How does Cluster Manager populate dmc_forwarder_assets input lookup csv table?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-does-Cluster-Manager-populate-dmc-forwarder-assets-input/m-p/696710#M10331</link>
      <description>&lt;P&gt;The forwarder asset table is generated from tcpin_connections metrics in _internal.&amp;nbsp; FTR, this is done by the Monitoring Console (MC), not the Cluster Manager (CM).&amp;nbsp; The CM and MC can be co-located in limited conditions - see &lt;A href="https://docs.splunk.com/Documentation/Splunk/9.3.0/Indexer/Systemrequirements#Additional_roles_for_the_manager_node" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.3.0/Indexer/Systemrequirements#Additional_roles_for_the_manager_node&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;Seeing the same forwarder many times often happens when a host is cloned without first preparing the forwarder for cloning.&amp;nbsp; See the CLONEPREP installer option at &lt;A href="https://docs.splunk.com/Documentation/Forwarder/9.3.0/Forwarder/InstallaWindowsuniversalforwarderfromaninstaller" target="_blank"&gt;https://docs.splunk.com/Documentation/Forwarder/9.3.0/Forwarder/InstallaWindowsuniversalforwarderfromaninstaller&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;The fix is to delete the GUID on each server (using the &lt;FONT face="courier new,courier"&gt;splunk clone-prep-clear-config&lt;/FONT&gt; command) and then restart Splunk so it generates a new GUID.&amp;nbsp; Then have the Monitoring Console generate a new forwarder assets table.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2024 12:16:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-does-Cluster-Manager-populate-dmc-forwarder-assets-input/m-p/696710#M10331</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-08-19T12:16:49Z</dc:date>
    </item>
  </channel>
</rss>

