Getting Data In

Why am I seeing multiple host names with duplicate client names in forwarder management?

louieb3
Path Finder

I am seeing multiple Host Names with duplicate Client Names in Forwarder Management. Why is this happening and how do I prevent it from happening?

0 Karma

mdsnmss
SplunkTrust
SplunkTrust

Duplicate "Client Name" or "Host Name"? Host name might occur if there was a previous installation of a Splunk Universal Forwarder on the system checking into the Deployment Server and it got reinstalled without reloading the deployment server. This would cause a duplicate since the new installation would have a different GUID.

Client Name is defined in deploymentclient.conf under the attribute clientName. It's default is "deploymentClient'. It can be customized to your needs for filtering in Server Classes in Forwarder Management. It isn't necessarily a bad thing to have duplicate values for this and can be used to create forwarder groups to filter on. It could be possible you have an add-on deployed to multiple clients that has this defined as well. The best way to find where this is configured on each system is to run:

splunk btool deploymentclient list --debug

You can change the value as necessary. If it is still in default you'll want to create the file in local rather than changing in default.

Get Updates on the Splunk Community!

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability As businesses scale ...