Installation

Issues with "missing" forwarder version after upgrade from universal forwarder 6.3.0 to 6.4.0?

ralphw_SAIC
Path Finder

i have upgraded all of our universal forwarders from 6.3.0 to 6.4.0 and roughly a third is showing as "missing" when looking at the forwarder version in the distributed management console. Is there any way to clean this up? I also notice a lot of servers that we have decommissioned showing up even after the log retention period of 90 days.

Labels (1)
1 Solution

ralphw_SAIC
Path Finder

Found how to clean up the database. It is under Settings > Monitoring Console > Settings > Forwarder Monitoring Setup > Rebuild forwarder assets.

View solution in original post

0 Karma

ralphw_SAIC
Path Finder

Found how to clean up the database. It is under Settings > Monitoring Console > Settings > Forwarder Monitoring Setup > Rebuild forwarder assets.

0 Karma

ddrillic
Ultra Champion

Have you updated the serverclass.conf on the deployment server? After all, that's the only place where we map the forwarder's host to the deployment app.

Deployment server architecture

0 Karma

ralphw_SAIC
Path Finder

No, no updates have been made to serverclass.conf. For the most part this is a stock install of Splunk with only the config files necessary to run changed(i.e. inputs, outputs, and the like). I have double checked the file and there is no specific server listed. It is a generic setup based on IP subnets and machine type. So I do not understand why with the upgrade i have ghosts hanging around showing up as missing.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...