Deployment Architecture

How to detect duplicate GUIDs on forwarders?

Contributor

There are a number of posts on how to fix duplicate GUIDs on FWDs (https://answers.splunk.com/answers/32368/duplicate-guids-for-cloned-forwarders-how-to-correct.html) but there are none for how to detect them to begin with.

How do I find duplicate GUIDs on forwarders?

1 Solution

Contributor

The DMC gets us most of the way there with the Forwarder management views. Some tweaking gets us here.

index=internal | dedup hostname
| search NOT [| inputlookup dmc
assets | dedup serverName | rename serverName as hostname | fields hostname]
| stats count(guid), values(hostname) by guid | sort - count(guid)

View solution in original post

Explorer

Sorry I know this is an older post but I was looking to do this as well and came up with this search that will show you any clients with the same GUID and the same name and only display multiples:

index=internal|dedup sourceIp
| search NOT [| inputlookup dmc
assets | dedup serverName | rename serverName as hostname | fields hostname]
| stats count(guid) AS dupguid, values(hostname), values(sourceIp) by guid|search dupguid > 1

0 Karma

Contributor

The DMC gets us most of the way there with the Forwarder management views. Some tweaking gets us here.

index=internal | dedup hostname
| search NOT [| inputlookup dmc
assets | dedup serverName | rename serverName as hostname | fields hostname]
| stats count(guid), values(hostname) by guid | sort - count(guid)

View solution in original post

Influencer

Another interesting statistic along these lines from that same Metrics log may be values(sourceIp) which I wonder if the assets table would help you or not...

0 Karma

SplunkTrust
SplunkTrust

There's also a tell-tale message at deployment server where you see something like "GUID XXX-XXX-XX has changed attributes to " .. I'll have to find one