Splunk Enterprise

Deployment Server issue after upgrading 9.1 to 9.4.5

verbal_666
Builder

Hello.

I'm having new issues after upgrading a DS from V.9.1 to V.9.4.5.
Every phone-home from the UFs (i have about 2000 UFs), gives a 0 [ZERO] in UI.
I can see UFs connected to 8089 of my DS Listener, many errors on Splunk logs,

AdminHandler:AuthenticationHandler [289178 TcpChannelThread] - Denied session token for user: splunk-system-user

On UFs i have the classic "deploymentclient.conf", with a simple,

[target-broker:deploymentServer]
targetUri = myDS:8089

With previous versions i never had issues.

Has something changed in 9.4 for UFs to DS connect?

Thanks.

verbal_666_0-1762334421144.png

 

0 Karma
1 Solution

PrewinThomas
Motivator

@verbal_666 

If it's after upgrading to 9.2+, add below configuration under outputs.conf in the deployment server, then restart splunk.

[indexAndForward]
index = true
selectiveIndexing = true

#https://community.splunk.com/t5/Deployment-Architecture/The-Client-forwarder-management-not-showing-...
#https://help.splunk.com/en/splunk-enterprise/administer/update-your-deployment/9.2/configure-the-dep...

Regards,
Prewin
🌟If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

View solution in original post

PrewinThomas
Motivator

@verbal_666 

If it's after upgrading to 9.2+, add below configuration under outputs.conf in the deployment server, then restart splunk.

[indexAndForward]
index = true
selectiveIndexing = true

#https://community.splunk.com/t5/Deployment-Architecture/The-Client-forwarder-management-not-showing-...
#https://help.splunk.com/en/splunk-enterprise/administer/update-your-deployment/9.2/configure-the-dep...

Regards,
Prewin
🌟If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

verbal_666
Builder

Ahhhhhhhhhhhhhhhhhhh!!! 😚

So the DS must index locally and then send data to Indexers... 👍👍👍

Thanks 👏👏

0 Karma

livehybrid
SplunkTrust
SplunkTrust

If for any reason you arent able to index locally using selectiveIndexing (e.g. small local disk) but can forward to your indexers then I have found that setting the Deployment Server up to be able to search against the search peers also fixes the UI and allows management of the agents without local indexing.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...