Splunk Search

How to avoid DCOM errors when de-commissioning servers?

clymbouris
Path Finder

I need to de-commission one of our Windows Servers which had a splunk forwarder installed. Once I uninstalled the forwarder I'm flooded with these errors on my splunk server (Windows-based):

Type=Error
User=NULL
ComputerName=splunk
OriginalComputerName=xxxxxxxxxx
wmi_type=WinEventLog:System
Message=DCOM was unable to communicate with the computer xxxxxxxxx using any of the configured protocols.

I've seen these errors come up when a server is down which is fine but I how can I make splunk realize that this server will be off for good?

Appreciated

Tags (2)
0 Karma

clymbouris
Path Finder

To answer my own newbie question I realized that aside from getting logs from splunk forwarders I also had remote inputs set individually for all my servers.

I had a feeling that this was really easy 🙂

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...