I am using Splunk Enterprise version 9.2.0.1 ( Upgraded from 9.0.5 to latest).
Before the upgrade, the Splunk deployment server is working as well.
When Splunk DS was upgraded to version 9.2.0.1, we saw issues with the client's server class.
Client name: EC2AMAZ-XXXXX
1. Client in DS server before upgraded (9.0.5)
Splunk
Server class: UF_input_WIN, UF_output
2. Client in DS server after upgraded (9.2.0.1)
Server class: UF_input_Linux, UF_output
The server class "UF_input_Linux" only filters by machine type Linux (see section 3 below). I did not know why this server class is applied to this windows client
3. "UF_input_Linux" Server class configuration
4. "UF_input_WIN" Server class configuration
Client is listed in the match list on UF_input_WIN server class
Is that a bug? The filter Machine type does not work correctly. I did not change any thing on server class & app when upgraded Splunk DS.
Does anyone know or meet this issue before?
Hi,
I am facing similar issue, please let us know when you find a solution.
Moreover, any of my Windows clients are not shown in the Server Classes. Although the apps are being deployed successfully. Any idea?
@tatdat171 had you opened up a case with support?
Yes, I have opened case on Customer support (same time as this post). But they are still troubleshooting.
@tatdat171 I have also recently opened a case with Splunk support and it's in queue, not acknowledge yet. Please let me know if you have any updates/finding. Thank you.
@tatdat171 are you able to resolve this issue? checking because we are experiencing same issue.
Hi @Hardy_0001 , I am still facing with this issue. Could you please help me share your solution?
Hi @Hardy_0001 , Splunk team confirmed that is a bug on Splunk version 9.2.0.1.
The Splunk Dev team is working on that. We can wait until they release fix version 😄