Deployment Architecture

Deployment monitor not showing accurate information on forwarders

remy06
Contributor

I've just upgrade a splunk server from 4.1.7 to 4.2.1.

After the upgrade,I enabled the deployment monitor and noticed that it prompts me about a number of missing forwarders.

the last connected time shown for those forwarders is the time I performed the upgrade.

However I did a search to check but those forwarders are actually active and is sending data.

0 Karma
1 Solution

Archana
Splunk Employee
Splunk Employee

Did the missing forwarders warning disappear after 24 hours? I can believe that you got the warning since we use a different definition to uniquely identify forwarders in the 4.2.1 version. Let us know if the warning persists past 24 hours (that's how far back the data is searched to look for missing forwarders).

View solution in original post

0 Karma

Archana
Splunk Employee
Splunk Employee

Did the missing forwarders warning disappear after 24 hours? I can believe that you got the warning since we use a different definition to uniquely identify forwarders in the 4.2.1 version. Let us know if the warning persists past 24 hours (that's how far back the data is searched to look for missing forwarders).

0 Karma
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...