Getting Data In

universal forwarder bug after update to V6

Ed_Alias
Path Finder

Hello,

since i updated my UF from version 5 to 6 they seem to loop on loading the serverclasses :

it seems like a loop keeps deploying new serverclass

03-27-2014 11:10:54.297 +0100 INFO DeployedServerclass - name=SC_windows_IIS_test Reload; workingDir='C:\Program Files\SplunkUniversalForwarder\var\run\SC_windows_IIS_test'
03-27-2014 11:10:54.297 +0100 INFO DeployedServerclass - name=SC_windows_iis Reload; workingDir='C:\Program Files\SplunkUniversalForwarder\var\run\SC_windows_iis'
03-27-2014 11:10:54.297 +0100 INFO DeployedServerclass - name=SC_windows_std_602 Reload; workingDir='C:\Program Files\SplunkUniversalForwarder\var\run\SC_windows_std_602'
03-27-2014 11:10:54.297 +0100 INFO DC:UpdateServerclassHandler - Changed state from=HandlingPhonehome to=Phonehome
03-27-2014 11:10:54.344 +0100 INFO DC:UpdateServerclassHandler - Changed state from=Phonehome to=HandlingPhonehome
03-27-2014 11:10:54.344 +0100 INFO DeployedServerclass - name=SC_windows_IIS_test Reload; workingDir='C:\Program Files\SplunkUniversalForwarder\var\run\SC_windows_IIS_test'
03-27-2014 11:10:54.344 +0100 INFO DeployedServerclass - name=SC_windows_iis Reload; workingDir='C:\Program Files\SplunkUniversalForwarder\var\run\SC_windows_iis'
03-27-2014 11:10:54.344 +0100 INFO DeployedServerclass - name=SC_windows_std_602 Reload; workingDir='C:\Program Files\SplunkUniversalForwarder\var\run\SC_windows_std_602'
03-27-2014 11:10:54.344 +0100 INFO DC:UpdateServerclassHandler - Changed state from=HandlingPhonehome to=Phonehome

0 Karma
1 Solution

sbennacer_splun
Splunk Employee
Splunk Employee

Hi,
The behavior you see is a Bug. i.e
SPL-78499:DC (deployment client) logging too verbose at default log levels
This Bug is expected to be addressed in coming releases 6.1 .
Kind Regards

View solution in original post

eugenezxq
New Member

Hi did you guys manage to resolve this issue? Am getting this right now.

0 Karma

sbennacer_splun
Splunk Employee
Splunk Employee

Hi,
The behavior you see is a Bug. i.e
SPL-78499:DC (deployment client) logging too verbose at default log levels
This Bug is expected to be addressed in coming releases 6.1 .
Kind Regards

Ed_Alias
Path Finder

yep thank you sbennacer !

0 Karma

Ed_Alias
Path Finder

what is precisely the (a) forwarder configs ?

0 Karma

Ed_Alias
Path Finder

and SC_windows_std_602 input.conf is :

[default]
evt_dc_name = \\server.domain

[WinEventLog:Application]
disabled = 0

[WinEventLog:Security]
disabled = 0

[WinEventLog:System]
disabled = 0'
0 Karma

Ed_Alias
Path Finder

SC_windows_IIS_test is not used anymore (it is empty)

here is the input for the conf_windows_IIS :

[monitor://L:\com\folder\...\*.log]
sourcetype=iis

index = test_index

[monitor://L:\com\folder\...\...\*.log]
sourcetype=iis

index = test_index


[monitor://L:\com\folder\...\...\...\*.log]
sourcetype=iis

index = test_index
recursive = true
0 Karma

koshyk
Super Champion

can you also update here .. (a) forwarder configs and (b) serverclass config

0 Karma
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...