I am using Splunk Enterprise version 9.2.0.1 ( Upgraded from 9.0.5 to latest). Before the upgrade, the Splunk deployment server is working as well. When Splunk DS was upgraded to version 9.2.0.1, we saw issues with the client's server class. Client name: EC2AMAZ-XXXXX 1. Client in DS server before upgraded (9.0.5) Splunk Server class: UF_input_WIN, UF_output 2. Client in DS server after upgraded (9.2.0.1) Server class: UF_input_Linux, UF_output The server class "UF_input_Linux" only filters by machine type Linux (see section 3 below). I did not know why this server class is applied to this windows client 3. "UF_input_Linux" Server class configuration 4. "UF_input_WIN" Server class configuration Client is listed in the match list on UF_input_WIN server class Is that a bug? The filter Machine type does not work correctly. I did not change any thing on server class & app when upgraded Splunk DS. Does anyone know or meet this issue before?
... View more