Getting Data In

Why are universal forwarders reporting error "Metric with the name thruput:thruput already registered"?

pilzi81
Explorer

Hi there,

By examining the _internal logs I found the following, Metric Error:

ERROR Metrics - Metric with name thruput:thruput already registered

It is reported by Universal Forwarders of several Clients spread over the entire day (with peaks in the morning hours - so I suppose that it's related to the client's start-up)

The interesting thing is, that all of these clients are still reporting events to the Indexers...

Questions:
Why does this happen?
And how can I avoid this?

thx

tskht
Loves-to-Learn Lots

When I installed and started Universal Forwarder 9.1.0.1, the following ERROR occurred:

ERROR Metrics - Metric with name='thruput:thruput' already registered
ERROR Metrics - Metric with name='thruput:idxSummary' already registered

Is this issue still persisting even with version 9.1.0.1?

0 Karma

LCanac31
New Member

Hello i have this issue on each restart of UF 7.0.8, is there some updates?
Thanks

0 Karma

jnew_splunk
Splunk Employee
Splunk Employee

This is a known Universal Forwarder issue (SPL-103209) effecting 6.3 and above. Currently there is no patch but the error is benign and can be ignored.

ss026381
Communicator

Although we see events from the forwarder but we see this error. Any idea what this error means?

0 Karma

Kieffer87
Communicator

We are also experiencing this on our universal forwarders.

adonio
Ultra Champion

do you get this error on both windows and linux forwarders or windows only?

0 Karma

pilzi81
Explorer

Since I created this thread I've seen this error on different UF versions (6.3.x, 6.4.x and our most recent UF version 6.5.3) as well as on different OS (windows, linux, macOS).

0 Karma

Kieffer87
Communicator

I get it on both but far more windows than linux. Also not all forwarders are experiencing this error despite running the same 6.5.3 version of Splunk.

0 Karma

skalliger
Motivator

Sorry for bringing up this old thread but are there any news about this? We ran into the same issue on our UF (version 6.5.0).

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...