Splunk Enterprise

Is there a work around for forwarders:deployment / duplicated forwarders?

amelguizo
New Member

Hello, 

I got duplicated forwarders reported in Cloud Monitoring Console. It appears the same amount of forwarders in active and missing status. Please, some workaround ? Rebuilding the forwarder asset could be and option ?

Forwarders report to Splunk Cloud through a Heavy Forwarder instance

(Splunk Cloud)

Thanks!

Labels (1)
0 Karma

x3ncrypt
Loves-to-Learn Everything

I have the same issue too. Cloud Monitoring Console was recently updated to a new version on 26/09. I have a ticket with Splunk technical support, it might be a bug.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

have you updated those by uninstalling and then installing a new version? If yes, then you have generated a new GUID for those UF and that means a new UF even it has the same name than earlier. When you are updating, just update it over old instance. 

You can get rid of those by rebuilding asset lookup as you suggested.


r. Ismo

0 Karma

amelguizo
New Member

Thanks for your answer!

I have rebuilt the asset lookup, but it didn't work. The number of forwarders still remains duplicated, half in active status, and the rest in active

Some suggestion ?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Can you give more information about this? Are all fwds duplicated and when those are switched to inactive and still in active? Are the name same, but GUID different etc?

0 Karma
Get Updates on the Splunk Community!

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...

Security Highlights | January 2023 Newsletter

January 2023 Splunk Security Essentials (SSE) 3.7.0 ReleaseThe free Splunk Security Essentials (SSE) 3.7.0 app ...

Platform Highlights | January 2023 Newsletter

 January 2023Peace on Earth and Peace of Mind With Business ResilienceAll organizations can start the new year ...