Getting Data In

Why am I seeing multiple host names with duplicate client names in forwarder management?

louieb3
Path Finder

I am seeing multiple Host Names with duplicate Client Names in Forwarder Management. Why is this happening and how do I prevent it from happening?

0 Karma

mdsnmss
SplunkTrust
SplunkTrust

Duplicate "Client Name" or "Host Name"? Host name might occur if there was a previous installation of a Splunk Universal Forwarder on the system checking into the Deployment Server and it got reinstalled without reloading the deployment server. This would cause a duplicate since the new installation would have a different GUID.

Client Name is defined in deploymentclient.conf under the attribute clientName. It's default is "deploymentClient'. It can be customized to your needs for filtering in Server Classes in Forwarder Management. It isn't necessarily a bad thing to have duplicate values for this and can be used to create forwarder groups to filter on. It could be possible you have an add-on deployed to multiple clients that has this defined as well. The best way to find where this is configured on each system is to run:

splunk btool deploymentclient list --debug

You can change the value as necessary. If it is still in default you'll want to create the file in local rather than changing in default.

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...