Deployment Architecture

Deployment Server Upgrade 9.2.1 and Server Class

tasteless_dove
Engager

Hi Everyone,

Is anyone else having issues with the Client tab not showing the correct Server Classes for the Host Names? For example, we have windows systems that are being labeled as Linux because we have a server class with a filter * but specific to linux-86_64 Machine Type. This almost gave me a heart attack because I thought the apps tied to this server class was going to replace the Windows ones.

However, when I go into the server class itself, the "Matched" tab only shows the devices that match the filter and when I check a handful of Windows devices itself, I don't see the apps that are tied with the Linux server class.

Wondering if anyone is experiencing this as well? And if so, if a fix is found.

Labels (1)

sylim_splunk
Splunk Employee
Splunk Employee
* Known issue:
This has been reported  and worked on by our Dev team. So far it is found to be a display issue that doesn't affect the functionality of the filter - We also acknowledge that it makes DS/DC harder to use for Splunk admins.
 
* Workaround:

There's no workaround for the bug - this issue only affects filtering on machine types, so if it’s possible to arrange some filters which won’t require machine types (like names, addresses, etc), these filters work. Obviously after fix they can return to more convenient machine types filters. 

 
* Fixed version:
The fix has been scheduled and will be available for the maintenance version 9.2.2. The GA is currently for  mid June, which is subject to change according to the build schedule/load.
 
If you still find it not work with 9.2.2 please check it with Splunk Support.
 
0 Karma

MNieddu
New Member

@sylim_splunk It's not just a display problem. Queries using the rest interface also return no results.

But the strange thing is that on some deployment servers it works without problems on the same version, but a large part does not allow rest on /services/deployment/server/clients.
On servers where the rest query don't work, there's also zero results under Forwarder Management/Clients.

Regards Marco

0 Karma

hschuhkn
Engager

This seems to fix the rest endpoint issue (esp. changes to outputs.conf).

https://docs.splunk.com/Documentation/Splunk/latest/Updating/Upgradepre-9.2deploymentservers

0 Karma

Gregski11
Contributor

not sure about that, but we are having major issues after the upgrade to 9.2.1 with both of our Deployment Servers (running on Windows Server 2019) 

one server is only supposed to show us Servers and the other is only supposed to show us our Workstations but now they are comingled on both, this poses a major problem as apps meant for servers may end up being installed on the Workstations and vice versa 

we opened a Technical Support case on this a week ago and will let you know how it goes, so far their work arounds are not fixing anything for us

0 Karma

jppasnak
Explorer

Any followup on this?   I am seeing the same issue.

0 Karma

kiran_panchavat
Contributor

@jppasnak 

Splunk team confirmed that is a bug on Splunk version 9.2.x. The Splunk Dev team is working on that. We can wait until they release fix version.   

You should create a support/bug ticket to Splunk Support.

** If this helps, please upvote or accept solution. **

jppasnak
Explorer

Thanks.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...