Getting Data In

Universal Forwarder has not removed itself from the DMC

Brolly75
New Member

I have had a host go down in aws that was not recoverable a few weeks ago and the universal forwarder is still showing as missing in the "distributed management console".

Does anyone know how to force its removal?

0 Karma
1 Solution

Jeremiah
Motivator

From the DMC documentation:

To remove a forwarder entirely from the DMC dashboards, click rebuild forwarder assets in Distributed Management Console > Settings > Forwarder Setup. This one time that you run this populating search, you can choose a lookback time. This selection does not change the 15 minute lookback time for the scheduled search or the data collection interval, both discussed above.

http://docs.splunk.com/Documentation/Splunk/6.3.2/DMC/Configureforwardermonitoring

View solution in original post

0 Karma

Jeremiah
Motivator

From the DMC documentation:

To remove a forwarder entirely from the DMC dashboards, click rebuild forwarder assets in Distributed Management Console > Settings > Forwarder Setup. This one time that you run this populating search, you can choose a lookback time. This selection does not change the 15 minute lookback time for the scheduled search or the data collection interval, both discussed above.

http://docs.splunk.com/Documentation/Splunk/6.3.2/DMC/Configureforwardermonitoring

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...