Hi,
A customer I am dealing with has a hybrid setup (UF, HF, DS on-prem) and the Rest of Infra in Splunk Cloud. There are 2800+ Universal Forwarders in a missing status. These were operational, however filtering was not setup correctly, so they blew the 150GB limit on Splunk Cloud. They decided to run an SCCM deployment to delete to the CONF files in UF configuration. Now, a re-install on the agent and trying to apply HF Config is not changing these statuses. Would a rebuild forwarder assets period set to 24 delete all HF with missing status and will these be discovered again?
https://community.splunk.com/t5/Getting-Data-In/How-far-back-can-be-go-when-rebuilding-the-forwarders-assets/m-p/249196
Or - Do we need to do a completed uninstall of UF package in SCCM, then re-deploy 9.0.2 with CONF files.
Thanks,
Stuart
... View more