Getting Data In

How does one fix the multiple Forwarders with same GUID issue on Windows boxes?

OldManEd
Builder

Everyone,

Here is my situation. I set up one Windows box with a Universal Forwarder, V6.3. This one forwarder was to be the one that all the many other forwarders would be cloned from. An older version of a Forwarder was placed on these other Windows boxes when another group created a Windows image. This older version was never set up properly.

In an effort to clean things up, the process that was used to re-do the Forwarders was the following;

  1. Stop the Forwarder service on the Windows box
  2. Delete the “C:\Program Files\SplunkUniversalForwarder\” directory.
  3. Copy in the new, updated, directory, “C:\Program Files\SplunkUniversalForwarder\”.
  4. Restart the service

Everything looked OK but I'm using a separate server as a Deployment server and monitoring server. When I went to the Distributed Management Console under Forwarders>Instance I see the message below;

Note: Multiple forwarders installed on one host appear with identical host names, but different GUIDs.

When I went through all the devices listed, I only saw one entry for each hostname but I noticed that the GUIDs were all the same.

Does anyone know what's going on and how I can clean this up?

Tags (2)
0 Karma
1 Solution

OldManEd
Builder

To address this issue, delete the file below and then restart the Splunk Forwarder.

 “C:\Program Files\SplunkUniversalForwarder\etc\instance.cfg”  

View solution in original post

OldManEd
Builder

To address this issue, delete the file below and then restart the Splunk Forwarder.

 “C:\Program Files\SplunkUniversalForwarder\etc\instance.cfg”  

OldManEd
Builder

After further review, I found that the issue is with the following file;

“C:\Program Files\SplunkUniversalForwarder\etc\instance.cfg”  

It contains the GUID entry. From what I read, I need to remove the "guid = " line and on the Forwarder restart, a new GUID should be generated.

My new question is, can I simply remove the entire file? The only thing in it is;

[general]
guid = <number>
0 Karma

OldManEd
Builder

After testing, it appears that deleting the "instance.cfg" file completely works fine. A new file is generated with a new GUID.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...