Hi
I hope you are doing well.
I have reinstalled the UF after that i found there are duplicate clients on the Deployment server and the monitoring console.
Q: Is there any way that we can refresh/rebuild/delete the old entries in the deployment servers?
#universal forwarder
Thanks for your help!
but there is no immediate deletion for the old entries?
At least earlier DS version "lost" old entries after you reboot it. Then those will be back when they have 1st connected into it. I'm not sure if this is still valid for current DS which are using index to store client information. I have never looked it with those versions.
At least from MC you could remove those old "missed" nodes by rebuild forwarder database.
MC -> Settings -> Forwarder Monitoring Setup then Rebuild forwarder assets button.
You should remember that this clears all old missed nodes over your selected time span.
Usually there is no need to reinstall UF. It's better to update it on place.
Another issue which you find after remove + install again is, that UF will reindexing all files what it still have on disk. The reason for that is, when you remove old installation you also remove local fishbucket index where UF has bookkeeping what it has already indexed.
Best practice is to preserve instance.cfg before reinstall. This keeps the GUID consistent and avoids duplicate entries on the Deployment Server and Monitoring Console.
If you wait a bit, the old entries will fade out on their own.
No manual deletion is required, entries are automatically cleaned up by Splunk after the clients stop phoning home for a period.
Regards,
Prewin
If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!