I am still getting information from all of the servers that have the universal forwarders on them and verified the service is running, but am still getting "missing forwarders" alert setup from initial setup search. Not sure what is going on. Also, looking at splunk logs for errors, found on each server the powershell script was failing inside: C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_windows\bin\powershell\dns-zoneinfo.ps1 Get-WMIObject : Invalid namespace "root\MicrosoftDNS" At C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_windows\bin\powershell\dns-zoneinfo.ps1:75 char:10 + $Zones = Get-WMIObject -Computer $ServerName -Namespace "root\Microso ... + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + CategoryInfo : InvalidArgument: (:) [Get-WmiObject], ManagementException + FullyQualifiedErrorId : GetWMIManagementException,Microsoft.PowerShell.Commands.GetWmiObjectCommand
... View more