Splunk Enterprise

Configure deployment clients and can't find it on the Forwarder Management page

Ntk
Loves-to-Learn Lots

I have tried installing Splunk Enterprise 9.2.0.1 on my Linux to use as a Forwarder tier But when I configure deployment clients from Universal Forwarder, the device list is not found. On the Forwarder Management page
So I tried to test it by uninstalling Splunk Enterprise 9.2.0.1 on Linux and installing Splunk Enterprise 9.1.3. Then I configured deployment clients from Universal Forwarder and found a list of devices. On the Forwarder Management page
So I'm wondering why I can't find the device entry. On the Forwarder page Management on Splunk Enterprise 9.2.0.1

Labels (2)
0 Karma

marnall
Builder

If I understand you correctly, you are configuring a linux host with a Splunk Enterprise installation (not Universal Forwarder installation?) and configuring it to retrieve deployment configurations from a second server, and you are saying that the first machine properly appears on the "Deployment Clients" interface of the second server when its on version 9.1.3 of Splunk but not on version 9.2.0.1?

0 Karma

Ntk
Loves-to-Learn Lots

Correct I configured a linux host with a Splunk Enterprise installation (not Universal Forwarder) and configured it to retrieve deployment configurations from a second server

0 Karma

marnall
Builder

Can you double-check that the configuration is correct on the deployment client? Using btool:

$SPLUNKHOME$/bin/splunk btool deploymentclient list
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...