Splunk Enterprise

Deployment Server issue after upgrading 9.1 to 9.4.5

verbal_666
Builder

Hello.

I'm having new issues after upgrading a DS from V.9.1 to V.9.4.5.
Every phone-home from the UFs (i have about 2000 UFs), gives a 0 [ZERO] in UI.
I can see UFs connected to 8089 of my DS Listener, many errors on Splunk logs,

AdminHandler:AuthenticationHandler [289178 TcpChannelThread] - Denied session token for user: splunk-system-user

On UFs i have the classic "deploymentclient.conf", with a simple,

[target-broker:deploymentServer]
targetUri = myDS:8089

With previous versions i never had issues.

Has something changed in 9.4 for UFs to DS connect?

Thanks.

verbal_666_0-1762334421144.png

 

0 Karma
1 Solution

PrewinThomas
Motivator

@verbal_666 

If it's after upgrading to 9.2+, add below configuration under outputs.conf in the deployment server, then restart splunk.

[indexAndForward]
index = true
selectiveIndexing = true

#https://community.splunk.com/t5/Deployment-Architecture/The-Client-forwarder-management-not-showing-...
#https://help.splunk.com/en/splunk-enterprise/administer/update-your-deployment/9.2/configure-the-dep...

Regards,
Prewin
🌟If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

View solution in original post

PrewinThomas
Motivator

@verbal_666 

If it's after upgrading to 9.2+, add below configuration under outputs.conf in the deployment server, then restart splunk.

[indexAndForward]
index = true
selectiveIndexing = true

#https://community.splunk.com/t5/Deployment-Architecture/The-Client-forwarder-management-not-showing-...
#https://help.splunk.com/en/splunk-enterprise/administer/update-your-deployment/9.2/configure-the-dep...

Regards,
Prewin
🌟If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

verbal_666
Builder

Ahhhhhhhhhhhhhhhhhhh!!! 😚

So the DS must index locally and then send data to Indexers... 👍👍👍

Thanks 👏👏

0 Karma

livehybrid
SplunkTrust
SplunkTrust

If for any reason you arent able to index locally using selectiveIndexing (e.g. small local disk) but can forward to your indexers then I have found that setting the Deployment Server up to be able to search against the search peers also fixes the UI and allows management of the agents without local indexing.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...