Splunk Enterprise

Request for Support: Forwarder Management Not Working After Upgrade to Splunk 9.4.0

Fa1
New Member

Dears,
Hope you are doing well,

I would like to request your assistance regarding an issue we've encountered after upgrading Splunk Enterprise from version 9.1.5 to 9.4.0. Since the upgrade, the Forwarder Management (Deployment Server) functionality is no longer working as expected.

Despite multiple troubleshooting attempts, the issue persists. I have attached a screenshot showing the specific error encountered.

I would greatly appreciate your guidance or recommendations to help resolve this matter. Please let me know if any additional logs or configuration details are needed.

 

Fa1_0-1753226807670.png

 

Thank you in advance for your support.
Labels (2)
0 Karma

user12214
New Member

for me it still not worked event after making sure the /etc/hosts file. i also double check my serverclass.conf and no syntax problem 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Have you used btool to check it? It could be defined in several apps + system/local and without btool it's almost impossible to see what you really have.

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Fa1 

Are you able to either post your serverclass.conf, or double check it to ensure no syntax errors within it? 

You could also try running a btool to check it:

$SPLUNK_HOME/bin/splunk cmd btool serverclass list --debug 

If this doesnt highlight any issues then it would be worth investigating a known issue at https://splunk.my.site.com/customer/s/article/After-upgrading-Splunk-from-v9-2-to-v9-4-the-Forwarder... which looks to be caused by a bad /etc/hosts file - The resolution of this issue is to edit the /etc/hosts file and use the correct format and entries, ensure it starts:

127.0.0.1 localhost localhost.localdomain localhost4 localhost4.localdomain4
::1       localhost localhost.localdomain localhost6 localhost6.localdomain6 

 

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

PrewinThomas
Motivator

@Fa1 
Seems like this is a known issue with 9.4.0.  Please check below for the workaround,

 

#https://splunk.my.site.com/customer/s/article/After-upgrading-Splunk-from-v9-2-to-v9-4-the-Forwarder...

Original post#https://community.splunk.com/t5/Splunk-Enterprise/Forwarder-Management-UI-error-on-new-install-9-4-0...

Regards,
Prewin
Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...