Getting Data In

universal forwarder bug after update to V6

Ed_Alias
Path Finder

Hello,

since i updated my UF from version 5 to 6 they seem to loop on loading the serverclasses :

it seems like a loop keeps deploying new serverclass

03-27-2014 11:10:54.297 +0100 INFO DeployedServerclass - name=SC_windows_IIS_test Reload; workingDir='C:\Program Files\SplunkUniversalForwarder\var\run\SC_windows_IIS_test'
03-27-2014 11:10:54.297 +0100 INFO DeployedServerclass - name=SC_windows_iis Reload; workingDir='C:\Program Files\SplunkUniversalForwarder\var\run\SC_windows_iis'
03-27-2014 11:10:54.297 +0100 INFO DeployedServerclass - name=SC_windows_std_602 Reload; workingDir='C:\Program Files\SplunkUniversalForwarder\var\run\SC_windows_std_602'
03-27-2014 11:10:54.297 +0100 INFO DC:UpdateServerclassHandler - Changed state from=HandlingPhonehome to=Phonehome
03-27-2014 11:10:54.344 +0100 INFO DC:UpdateServerclassHandler - Changed state from=Phonehome to=HandlingPhonehome
03-27-2014 11:10:54.344 +0100 INFO DeployedServerclass - name=SC_windows_IIS_test Reload; workingDir='C:\Program Files\SplunkUniversalForwarder\var\run\SC_windows_IIS_test'
03-27-2014 11:10:54.344 +0100 INFO DeployedServerclass - name=SC_windows_iis Reload; workingDir='C:\Program Files\SplunkUniversalForwarder\var\run\SC_windows_iis'
03-27-2014 11:10:54.344 +0100 INFO DeployedServerclass - name=SC_windows_std_602 Reload; workingDir='C:\Program Files\SplunkUniversalForwarder\var\run\SC_windows_std_602'
03-27-2014 11:10:54.344 +0100 INFO DC:UpdateServerclassHandler - Changed state from=HandlingPhonehome to=Phonehome

0 Karma
1 Solution

sbennacer_splun
Splunk Employee
Splunk Employee

Hi,
The behavior you see is a Bug. i.e
SPL-78499:DC (deployment client) logging too verbose at default log levels
This Bug is expected to be addressed in coming releases 6.1 .
Kind Regards

View solution in original post

eugenezxq
New Member

Hi did you guys manage to resolve this issue? Am getting this right now.

0 Karma

sbennacer_splun
Splunk Employee
Splunk Employee

Hi,
The behavior you see is a Bug. i.e
SPL-78499:DC (deployment client) logging too verbose at default log levels
This Bug is expected to be addressed in coming releases 6.1 .
Kind Regards

Ed_Alias
Path Finder

yep thank you sbennacer !

0 Karma

Ed_Alias
Path Finder

what is precisely the (a) forwarder configs ?

0 Karma

Ed_Alias
Path Finder

and SC_windows_std_602 input.conf is :

[default]
evt_dc_name = \\server.domain

[WinEventLog:Application]
disabled = 0

[WinEventLog:Security]
disabled = 0

[WinEventLog:System]
disabled = 0'
0 Karma

Ed_Alias
Path Finder

SC_windows_IIS_test is not used anymore (it is empty)

here is the input for the conf_windows_IIS :

[monitor://L:\com\folder\...\*.log]
sourcetype=iis

index = test_index

[monitor://L:\com\folder\...\...\*.log]
sourcetype=iis

index = test_index


[monitor://L:\com\folder\...\...\...\*.log]
sourcetype=iis

index = test_index
recursive = true
0 Karma

koshyk
Super Champion

can you also update here .. (a) forwarder configs and (b) serverclass config

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...