I upgraded from 6.1.4 to 6.2 for the server and the universal forwarders. Afterwards there are duplicate entries on the All Forwarders screen for each server; one with the ip address as the Forwarder designation and another with the fqdn. The record with the ip address shows:
Splunk version: pre 4.2
Platform: n/a
Last Connected: updating every ten minutes
Current Status: missing
The record with the fqdn, shows 6.2 for the version and all of the other information like before the upgrade. I thought that the records with the ip address would be cleaned up after 24 hours since they have a status of missing but since the connection time still updates they have remained.
Any clue as two why there are two forwarder records? And how would I clear up the ones that have the ip address as the forwarder name?
... View more