Deployment Architecture

Forwarder Management Issue

jafaruddinlie
Engager

Hi all
I am getting this message on Splunk 6.2.0 after upgrading from 5:

The forwarder management interface does not support some settings in your serverclass.conf file. The interface is now read-only.

One of the offending lines (from the search): WARN DS_DC_Common - Attribute unsupported by UI: stanza=serverClass:windows property=filterType reason='unsupported at this level' The stanza looks OK in the conf file.

The screen is now in read-only mode, can anyone help me with this? Thanks!

Tags (1)
0 Karma
1 Solution

lguinn2
Legend

filterType is not supported by Forwarder Management at any level. You must remove all filterType attributes from serverclass.conf
if you want to use Forwarder Management.

Here is a List of incompatibilities between the old serverclass.conf and what is supported by Forwarder Management.

View solution in original post

0 Karma

lguinn2
Legend

filterType is not supported by Forwarder Management at any level. You must remove all filterType attributes from serverclass.conf
if you want to use Forwarder Management.

Here is a List of incompatibilities between the old serverclass.conf and what is supported by Forwarder Management.

0 Karma

carmitstead
Explorer

Found it. Instead of finding it in my deploymentclient app's serverclass.conf, I found the filterType directives in my $SPLUNK_HOME/etc/system/local/serverclass.conf. They are commented and the errors are gone.

0 Karma

carmitstead
Explorer

Thanks for the answer. I don't have it specified anywhere that I know of. But I'll do a thorough check.

carmitstead
Explorer

I'm also getting this error message. The filterType directive is not declared at the global or app level at all. Thinking that I have to declare it in each stanza?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...