Splunk Enterprise

Missing forwarders and PowerShell DNS script failures

Lost_n_da_sauce
Observer

I am still getting information from all of the servers that have the universal forwarders on them and verified the service is running, but am still getting "missing forwarders" alert setup from initial setup search. Not sure what is going on.

Also, looking at splunk logs for errors, found on each server the powershell script was failing inside:

C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_windows\bin\powershell\dns-zoneinfo.ps1

Get-WMIObject : Invalid namespace "root\MicrosoftDNS"
At C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_windows\bin\powershell\dns-zoneinfo.ps1:75 char:10
+ $Zones = Get-WMIObject -Computer $ServerName -Namespace "root\Microso ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : InvalidArgument: (:) [Get-WmiObject], ManagementException
+ FullyQualifiedErrorId : GetWMIManagementException,Microsoft.PowerShell.Commands.GetWmiObjectCommand

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...