This topic lists known issues that are specific to the universal forwarder.
|Publication date||Defect number||Description|
||Dropped events messages in splunkd are INFO; should be WARN.|
|2015-7-7||SPL-99316||Universal Forwarders stop sending data repeatedly throughout the day. To workaround, in limits.conf, try changing |
|2015-7-7||SPL-99796||Universal Forwarder Crashing thread: Main Thread - Access violation, cannot read at address. The workaround is to remove the migrated script input: [script://$SPLUNK_HOME\bin\scripts\splunk-regmon.path]|
|2014-10-28||SPL-88396||After configuring a client name for a deployment client, the name is not shown in the Forwarder Management UI.
Workaround: Create a server class, where you can see the client name, and use that group when you add data.
|2014-10-28||SPL-92303||Some events are line broken improperly when forwarding from a universal forwarder, leading to a possible event count mismatch with expected results.|
|2015-7-7||SPL-99687||Splunk universal forwarder is 7-10 days behind recent Windows Security and system log events. To mitigate this, edit the following stanza in |
[WinEventLog://Security] evt_resolve_ad_obj = 0
|Pre-6.2||SPL-74427||The Splunk universal forwarder installer for Solaris 10 does not add the |
Troubleshoot the universal forwarder with Splunk Enterprise
This documentation applies to the following versions of Splunk® Universal Forwarder: 6.4.1, 6.4.2