At the time this answer was written, duplicate GUIDs may not have meant anything (before my time working with splunk). When using a deployment server, or looking anything up based on GUID, this becomes pretty important. Please fix this issue by stopping splunk, deleting instance.cfg, and starting splunk: 1. Stop Splunk 2. Delete instance.cfg (c:\Program Files\Splunk\etc\instance.cfg c:\Program Files\SplunkUniversalForwarder\etc\instance.cfg /opt/splunk/etc/instance.cfg /opt/splunkuniversalforwarder/etc/instance.cfg) 3. Start Splunk Problem solved. BTW, whatever the root cause, check the server.conf to make sure the system name is correct, otherwise you could have multiple systems sending logs as the same host.
... View more