Getting Data In

Why are universal forwarders reporting error "Metric with the name thruput:thruput already registered"?

pilzi81
Explorer

Hi there,

By examining the _internal logs I found the following, Metric Error:

ERROR Metrics - Metric with name thruput:thruput already registered

It is reported by Universal Forwarders of several Clients spread over the entire day (with peaks in the morning hours - so I suppose that it's related to the client's start-up)

The interesting thing is, that all of these clients are still reporting events to the Indexers...

Questions:
Why does this happen?
And how can I avoid this?

thx

tskht
Loves-to-Learn

When I installed and started Universal Forwarder 9.1.0.1, the following ERROR occurred:

ERROR Metrics - Metric with name='thruput:thruput' already registered
ERROR Metrics - Metric with name='thruput:idxSummary' already registered

Is this issue still persisting even with version 9.1.0.1?

0 Karma

LCanac31
New Member

Hello i have this issue on each restart of UF 7.0.8, is there some updates?
Thanks

0 Karma

jnew_splunk
Splunk Employee
Splunk Employee

This is a known Universal Forwarder issue (SPL-103209) effecting 6.3 and above. Currently there is no patch but the error is benign and can be ignored.

ss026381
Communicator

Although we see events from the forwarder but we see this error. Any idea what this error means?

0 Karma

Kieffer87
Communicator

We are also experiencing this on our universal forwarders.

adonio
Ultra Champion

do you get this error on both windows and linux forwarders or windows only?

0 Karma

pilzi81
Explorer

Since I created this thread I've seen this error on different UF versions (6.3.x, 6.4.x and our most recent UF version 6.5.3) as well as on different OS (windows, linux, macOS).

0 Karma

Kieffer87
Communicator

I get it on both but far more windows than linux. Also not all forwarders are experiencing this error despite running the same 6.5.3 version of Splunk.

0 Karma

skalliger
SplunkTrust
SplunkTrust

Sorry for bringing up this old thread but are there any news about this? We ran into the same issue on our UF (version 6.5.0).

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...