Deployment Architecture

Forwarder Management - Duplicated hosts

mikelanghorst
Motivator

Recently I looked at the Forwarder Management page, and selected the "Phone Home: Later than Expected". A large number of hosts were listed here, but when I filtered for the individual hosts, and set it back to Phone Home: All, I found that the host was listed multiple times.

Now some of them were likely related to DHCP IP's being changed. But several of them have static IP's.

The page shows that the Host Name, Client Name, IP Address, are all the same. Yet one entry shows a Phone Home of 12 hours ago, while the other shows a few seconds ago.

Why the duplicates?

Tags (1)
0 Karma

mikelanghorst
Motivator

After opening a support case, I was told this was a known bug being worked on and should be in an upcoming release. The OpenSSL bug was the only fix for 6.0.3, so I'd expect it to likely be in 6.0.4.

cedarcrestone
Explorer

I have started to see the same behavior in our environment. I wish there was a way to see the duplicate ones and have those removed either automatically or some other way.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...