Getting Data In

Why am I seeing multiple host names with duplicate client names in forwarder management?

louieb3
Path Finder

I am seeing multiple Host Names with duplicate Client Names in Forwarder Management. Why is this happening and how do I prevent it from happening?

0 Karma

mdsnmss
SplunkTrust
SplunkTrust

Duplicate "Client Name" or "Host Name"? Host name might occur if there was a previous installation of a Splunk Universal Forwarder on the system checking into the Deployment Server and it got reinstalled without reloading the deployment server. This would cause a duplicate since the new installation would have a different GUID.

Client Name is defined in deploymentclient.conf under the attribute clientName. It's default is "deploymentClient'. It can be customized to your needs for filtering in Server Classes in Forwarder Management. It isn't necessarily a bad thing to have duplicate values for this and can be used to create forwarder groups to filter on. It could be possible you have an add-on deployed to multiple clients that has this defined as well. The best way to find where this is configured on each system is to run:

splunk btool deploymentclient list --debug

You can change the value as necessary. If it is still in default you'll want to create the file in local rather than changing in default.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...