Splunk Enterprise

Request for Support: Forwarder Management Not Working After Upgrade to Splunk 9.4.0

Fa1
New Member

Dears,
Hope you are doing well,

I would like to request your assistance regarding an issue we've encountered after upgrading Splunk Enterprise from version 9.1.5 to 9.4.0. Since the upgrade, the Forwarder Management (Deployment Server) functionality is no longer working as expected.

Despite multiple troubleshooting attempts, the issue persists. I have attached a screenshot showing the specific error encountered.

I would greatly appreciate your guidance or recommendations to help resolve this matter. Please let me know if any additional logs or configuration details are needed.

 

Fa1_0-1753226807670.pngFa1_0-1753226807670.png

 

Thank you in advance for your support.
Labels (2)
0 Karma

user12214
New Member

for me it still not worked event after making sure the /etc/hosts file. i also double check my serverclass.conf and no syntax problem 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Have you used btool to check it? It could be defined in several apps + system/local and without btool it's almost impossible to see what you really have.

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Fa1 

Are you able to either post your serverclass.conf, or double check it to ensure no syntax errors within it? 

You could also try running a btool to check it:

$SPLUNK_HOME/bin/splunk cmd btool serverclass list --debug 

If this doesnt highlight any issues then it would be worth investigating a known issue at https://splunk.my.site.com/customer/s/article/After-upgrading-Splunk-from-v9-2-to-v9-4-the-Forwarder... which looks to be caused by a bad /etc/hosts file - The resolution of this issue is to edit the /etc/hosts file and use the correct format and entries, ensure it starts:

127.0.0.1 localhost localhost.localdomain localhost4 localhost4.localdomain4
::1       localhost localhost.localdomain localhost6 localhost6.localdomain6 

 

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

PrewinThomas
Motivator

@Fa1 
Seems like this is a known issue with 9.4.0.  Please check below for the workaround,

 

#https://splunk.my.site.com/customer/s/article/After-upgrading-Splunk-from-v9-2-to-v9-4-the-Forwarder...

Original post#https://community.splunk.com/t5/Splunk-Enterprise/Forwarder-Management-UI-error-on-new-install-9-4-0...

Regards,
Prewin
Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...