Getting Data In

Why are universal forwarders reporting error "Metric with the name thruput:thruput already registered"?

pilzi81
Explorer

Hi there,

By examining the _internal logs I found the following, Metric Error:

ERROR Metrics - Metric with name thruput:thruput already registered

It is reported by Universal Forwarders of several Clients spread over the entire day (with peaks in the morning hours - so I suppose that it's related to the client's start-up)

The interesting thing is, that all of these clients are still reporting events to the Indexers...

Questions:
Why does this happen?
And how can I avoid this?

thx

tskht
Loves-to-Learn Lots

When I installed and started Universal Forwarder 9.1.0.1, the following ERROR occurred:

ERROR Metrics - Metric with name='thruput:thruput' already registered
ERROR Metrics - Metric with name='thruput:idxSummary' already registered

Is this issue still persisting even with version 9.1.0.1?

0 Karma

LCanac31
New Member

Hello i have this issue on each restart of UF 7.0.8, is there some updates?
Thanks

0 Karma

jnew_splunk
Splunk Employee
Splunk Employee

This is a known Universal Forwarder issue (SPL-103209) effecting 6.3 and above. Currently there is no patch but the error is benign and can be ignored.

ss026381
Communicator

Although we see events from the forwarder but we see this error. Any idea what this error means?

0 Karma

Kieffer87
Communicator

We are also experiencing this on our universal forwarders.

adonio
Ultra Champion

do you get this error on both windows and linux forwarders or windows only?

0 Karma

pilzi81
Explorer

Since I created this thread I've seen this error on different UF versions (6.3.x, 6.4.x and our most recent UF version 6.5.3) as well as on different OS (windows, linux, macOS).

0 Karma

Kieffer87
Communicator

I get it on both but far more windows than linux. Also not all forwarders are experiencing this error despite running the same 6.5.3 version of Splunk.

0 Karma

skalliger
Motivator

Sorry for bringing up this old thread but are there any news about this? We ran into the same issue on our UF (version 6.5.0).

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...