Deployment Architecture

Forwarder management error

vrmandadi
Builder

I am getting the below error

The forwarder management interface does not support some settings in your serverclass.conf file. The interface is now read-only.

I was just navigating through the UI and tried creating a new serverclass but did not save anything but still the serverclass is showing in the deployment server.I tried deleting through the CLI in the serverclass.conf but I have not seen that

I have read in some post that it is because of filterType this causes the error.Any suggestions what is the best solution.Below is the stanza I have in few serverclass amd similar issue
machineTypesFilter = linux-i686,linux-x86_64,

https://answers.splunk.com/answers/185547/forwarder-management-issue.html

0 Karma

vrmandadi
Builder

I figured it out .The app created is under
/opt/splunk/etc/apps/search/local/serverclass.conf .I deleted the and the error has gone

0 Karma

prakash007
Builder

I think the message you are seeing is expected on deployment server, you can't manage all the configs via deployment server web-interface..
check you repositoryLocation on your deloyment server(they usually reside under $SPLUNK_HOME/etc/deployment-apps), whereas on deployment clients they are downloaded under $SPLUNK_HOME/etc/apps

https://docs.splunk.com/Documentation/Splunk/7.2.1/Updating/Createdeploymentapps

0 Karma

vrmandadi
Builder

What should I need to check specifically

0 Karma

prakash007
Builder

As you deleted the server class from CLI and If you are still seeing the serverclass you created from deployment-server UI, I would restart splunkd on deployment-server.
what's the exact error you are seeing..??
did you follow the splunkanswers resolution you posted in your question..??

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...