Deployment Architecture

Deployment Server: Duplicate clients after reinstalling the UF

AliMaher
Path Finder

Hi 
I hope you are doing well.

 

I have reinstalled the UF after that i found there are duplicate clients on the Deployment server and the monitoring console.

Q: Is there any way that we can refresh/rebuild/delete the old entries in the deployment servers?

#universal forwarder

0 Karma

AliMaher
Path Finder

Thanks for your help!

but there is no immediate deletion for the old entries?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

At least earlier DS version "lost" old entries after you reboot it. Then those will be back when they have 1st connected into it. I'm not sure if this is still valid for current DS which are using index to store client information. I have never looked it with those versions.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

At least from MC you could remove those old "missed" nodes by rebuild forwarder database.

MC -> Settings -> Forwarder Monitoring Setup then Rebuild forwarder assets button.
You should remember that this clears all old missed nodes over your selected time span.

Usually there is no need to reinstall UF. It's better to update it on place.

Another issue which you find after remove + install again is, that UF will reindexing all files what it still have on disk. The reason for that is, when you remove old installation you also remove local fishbucket index where UF has bookkeeping what it has already indexed.

PrewinThomas
Motivator

@AliMaher 

Best practice is to preserve instance.cfg before reinstall. This keeps the GUID consistent and avoids duplicate entries on the Deployment Server and Monitoring Console.
If you wait a bit, the old entries will fade out on their own.
No manual deletion is required, entries are automatically cleaned up by Splunk after the clients stop phoning home for a period.

Regards,
Prewin
If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...