Splunk Enterprise

Deployment Server issue after upgrading 9.1 to 9.4.5

verbal_666
Builder

Hello.

I'm having new issues after upgrading a DS from V.9.1 to V.9.4.5.
Every phone-home from the UFs (i have about 2000 UFs), gives a 0 [ZERO] in UI.
I can see UFs connected to 8089 of my DS Listener, many errors on Splunk logs,

AdminHandler:AuthenticationHandler [289178 TcpChannelThread] - Denied session token for user: splunk-system-user

On UFs i have the classic "deploymentclient.conf", with a simple,

[target-broker:deploymentServer]
targetUri = myDS:8089

With previous versions i never had issues.

Has something changed in 9.4 for UFs to DS connect?

Thanks.

verbal_666_0-1762334421144.png

 

0 Karma
1 Solution

PrewinThomas
Motivator

@verbal_666 

If it's after upgrading to 9.2+, add below configuration under outputs.conf in the deployment server, then restart splunk.

[indexAndForward]
index = true
selectiveIndexing = true

#https://community.splunk.com/t5/Deployment-Architecture/The-Client-forwarder-management-not-showing-...
#https://help.splunk.com/en/splunk-enterprise/administer/update-your-deployment/9.2/configure-the-dep...

Regards,
Prewin
🌟If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

View solution in original post

PrewinThomas
Motivator

@verbal_666 

If it's after upgrading to 9.2+, add below configuration under outputs.conf in the deployment server, then restart splunk.

[indexAndForward]
index = true
selectiveIndexing = true

#https://community.splunk.com/t5/Deployment-Architecture/The-Client-forwarder-management-not-showing-...
#https://help.splunk.com/en/splunk-enterprise/administer/update-your-deployment/9.2/configure-the-dep...

Regards,
Prewin
🌟If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

verbal_666
Builder

Ahhhhhhhhhhhhhhhhhhh!!! 😚

So the DS must index locally and then send data to Indexers... 👍👍👍

Thanks 👏👏

0 Karma

livehybrid
SplunkTrust
SplunkTrust

If for any reason you arent able to index locally using selectiveIndexing (e.g. small local disk) but can forward to your indexers then I have found that setting the Deployment Server up to be able to search against the search peers also fixes the UI and allows management of the agents without local indexing.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...