All Apps and Add-ons
Highlighted

Recently upgraded a Splunk Universal forwarder from 6.1.2 to 6.2.2, but why is S.o.S - Splunk on Splunk still showing the UF version as 6.1.2?

Path Finder

We have upgraded a Splunk universal forwarder from Splunk 6.1.2 to 6.2.2 a couple of days back. I checked the version in the forwarder after upgrading, using the ./splunk version command and it showed "Splunk Universal Forwarder 6.2.2 (build 255606)", but the S.o.S - Splunk on Splunk app on the search head still shows the Universal Forwarder version as 6.1.2 under deployment Status> Deployment Topology.

I checked the splunkinstancesinfo.csv lookup table for hints and it too has the UF version listed as 6.1.2.

The Search head itself is running Splunk 6.2.2 (if that matters). I have restarted the Search head a couple of times, but it's not picking up the correct Splunk UF version. Can anyone help?

Thanks,
Saikat

Highlighted

Re: Recently upgraded a Splunk Universal forwarder from 6.1.2 to 6.2.2, but why is S.o.S - Splunk on Splunk still showing the UF version as 6.1.2?

Splunk Employee
Splunk Employee

Clean the sos lookups, and next time it's re-populated, it should refresh the list of forwarders.

0 Karma