Splunk Enterprise

Request for Support: Forwarder Management Not Working After Upgrade to Splunk 9.4.0

Fa1
New Member

Dears,
Hope you are doing well,

I would like to request your assistance regarding an issue we've encountered after upgrading Splunk Enterprise from version 9.1.5 to 9.4.0. Since the upgrade, the Forwarder Management (Deployment Server) functionality is no longer working as expected.

Despite multiple troubleshooting attempts, the issue persists. I have attached a screenshot showing the specific error encountered.

I would greatly appreciate your guidance or recommendations to help resolve this matter. Please let me know if any additional logs or configuration details are needed.

 

Fa1_0-1753226807670.pngFa1_0-1753226807670.png

 

Thank you in advance for your support.
Labels (2)
0 Karma

user12214
New Member

for me it still not worked event after making sure the /etc/hosts file. i also double check my serverclass.conf and no syntax problem 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Have you used btool to check it? It could be defined in several apps + system/local and without btool it's almost impossible to see what you really have.

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Fa1 

Are you able to either post your serverclass.conf, or double check it to ensure no syntax errors within it? 

You could also try running a btool to check it:

$SPLUNK_HOME/bin/splunk cmd btool serverclass list --debug 

If this doesnt highlight any issues then it would be worth investigating a known issue at https://splunk.my.site.com/customer/s/article/After-upgrading-Splunk-from-v9-2-to-v9-4-the-Forwarder... which looks to be caused by a bad /etc/hosts file - The resolution of this issue is to edit the /etc/hosts file and use the correct format and entries, ensure it starts:

127.0.0.1 localhost localhost.localdomain localhost4 localhost4.localdomain4
::1       localhost localhost.localdomain localhost6 localhost6.localdomain6 

 

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

PrewinThomas
Motivator

@Fa1 
Seems like this is a known issue with 9.4.0.  Please check below for the workaround,

 

#https://splunk.my.site.com/customer/s/article/After-upgrading-Splunk-from-v9-2-to-v9-4-the-Forwarder...

Original post#https://community.splunk.com/t5/Splunk-Enterprise/Forwarder-Management-UI-error-on-new-install-9-4-0...

Regards,
Prewin
Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...