Getting Data In

Deployment server only showing 1 client at a time

pfabrizi
Path Finder

I have only a deployment server at the current time and to get ahead of the game we going to roll the UF to our windows servers as this can take months. My deployment server has no apps, so it is just the client reporting. I currently have configured 2 client but only 1 shows up at a time. If one is showing and I bounce the other client splunk service it will show but the other client disappears?

0 Karma

maraman_splunk
Splunk Employee
Splunk Employee

Hi,

have you cloned the UF as it would explain why you only see one ?
if that's the case, use the splunk clone-prep-clear-config
read http://docs.splunk.com/Documentation/Forwarder/latest/Forwarder/Makeauniversalforwarderpartofahostim... for more info.

If that's not the case look for duplicate value in the name /clientname sent by your UF

0 Karma

pfabrizi
Path Finder

should this be done before I create the image or can it done as part of the install script?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Cloud Application Management in Terraform

Now On-Demand   We’re diving into how you can bring Infrastructure as Code (IaC) principles to your Splunk ...

What's New in Splunk Enterprise Security (ES) 8.6

Purpose-Built AI Agents for the Agentic SOC  Splunk Enterprise Security 8.6 expands AI in Security with ...

From Raw Data to Executive-Ready Stories, Faster

Build Data Stories for Every Audience  A dashboard is rarely just a dashboard. It might be the view an ...