Deployment Architecture

Unable to remove records from the Deployment Server

TF39
Engager

Hi guys, i'm in need to delete some records from the deployment server although, when i do it via the forwarder management i get the "This functionality has been deprecated" alert. Is there any other way i can proceed?

Labels (1)

TheDairyGuy
Explorer

I had the same issue.  The UF was installed improperly initially, but was showing it reported into the deployment server.  So, the UF was uninstalled, and reinstalled.  It created a new instance in the Deployment server, and will not go away.  I'm curious how I am supposed to deal with this.  I am curious also - will it drop off over time, or is there a way I can go into a config file or something and delete it via CLI?

0 Karma

TheDairyGuy
Explorer

I did have luck running the following command on the deployment server under:

directory: /opt/splunk/bin

./splunk reload deploy-server

After the reload the other instance disappeared.

0 Karma

reddsbaron
Observer

I see the same issue with trying to delete a duplicate and it never goes away

0 Karma

kfinn
Explorer

I'm seeing this same behavior since upgrade of Splunk HF to version 9.2.2. There is a server that has been retired, usually I would delete the record, and if that system comes back online for any reason it would show back up. Is there another way to remove, or will it drop off over time?

Kevin

0 Karma

FTS2020
Observer

I had this same issue on a new install of Splunk, clients that still didnt have universal forwarder remove were connecting to this new instance. After removing the UF from those machines I was trying to delete from client list and was receiving this message and would not go away. I needed to reenable deployment server on the new instance in order for me to delete clients by running the following command. Worked for me hope it helps.

sudo /opt/splunk/bin/splunk enable deploy-server
sudo /opt/splunk/bin/splunk restart



0 Karma
Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...