Getting Data In

universal forwarder bug after update to V6

Ed_Alias
Path Finder

Hello,

since i updated my UF from version 5 to 6 they seem to loop on loading the serverclasses :

it seems like a loop keeps deploying new serverclass

03-27-2014 11:10:54.297 +0100 INFO DeployedServerclass - name=SC_windows_IIS_test Reload; workingDir='C:\Program Files\SplunkUniversalForwarder\var\run\SC_windows_IIS_test'
03-27-2014 11:10:54.297 +0100 INFO DeployedServerclass - name=SC_windows_iis Reload; workingDir='C:\Program Files\SplunkUniversalForwarder\var\run\SC_windows_iis'
03-27-2014 11:10:54.297 +0100 INFO DeployedServerclass - name=SC_windows_std_602 Reload; workingDir='C:\Program Files\SplunkUniversalForwarder\var\run\SC_windows_std_602'
03-27-2014 11:10:54.297 +0100 INFO DC:UpdateServerclassHandler - Changed state from=HandlingPhonehome to=Phonehome
03-27-2014 11:10:54.344 +0100 INFO DC:UpdateServerclassHandler - Changed state from=Phonehome to=HandlingPhonehome
03-27-2014 11:10:54.344 +0100 INFO DeployedServerclass - name=SC_windows_IIS_test Reload; workingDir='C:\Program Files\SplunkUniversalForwarder\var\run\SC_windows_IIS_test'
03-27-2014 11:10:54.344 +0100 INFO DeployedServerclass - name=SC_windows_iis Reload; workingDir='C:\Program Files\SplunkUniversalForwarder\var\run\SC_windows_iis'
03-27-2014 11:10:54.344 +0100 INFO DeployedServerclass - name=SC_windows_std_602 Reload; workingDir='C:\Program Files\SplunkUniversalForwarder\var\run\SC_windows_std_602'
03-27-2014 11:10:54.344 +0100 INFO DC:UpdateServerclassHandler - Changed state from=HandlingPhonehome to=Phonehome

0 Karma
1 Solution

sbennacer_splun
Splunk Employee
Splunk Employee

Hi,
The behavior you see is a Bug. i.e
SPL-78499:DC (deployment client) logging too verbose at default log levels
This Bug is expected to be addressed in coming releases 6.1 .
Kind Regards

View solution in original post

eugenezxq
New Member

Hi did you guys manage to resolve this issue? Am getting this right now.

0 Karma

sbennacer_splun
Splunk Employee
Splunk Employee

Hi,
The behavior you see is a Bug. i.e
SPL-78499:DC (deployment client) logging too verbose at default log levels
This Bug is expected to be addressed in coming releases 6.1 .
Kind Regards

Ed_Alias
Path Finder

yep thank you sbennacer !

0 Karma

Ed_Alias
Path Finder

what is precisely the (a) forwarder configs ?

0 Karma

Ed_Alias
Path Finder

and SC_windows_std_602 input.conf is :

[default]
evt_dc_name = \\server.domain

[WinEventLog:Application]
disabled = 0

[WinEventLog:Security]
disabled = 0

[WinEventLog:System]
disabled = 0'
0 Karma

Ed_Alias
Path Finder

SC_windows_IIS_test is not used anymore (it is empty)

here is the input for the conf_windows_IIS :

[monitor://L:\com\folder\...\*.log]
sourcetype=iis

index = test_index

[monitor://L:\com\folder\...\...\*.log]
sourcetype=iis

index = test_index


[monitor://L:\com\folder\...\...\...\*.log]
sourcetype=iis

index = test_index
recursive = true
0 Karma

koshyk
Super Champion

can you also update here .. (a) forwarder configs and (b) serverclass config

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...