Known issues
This topic lists known issues that are specific to the universal forwarder. For information on fixed issues, see Fixed issues.
Universal forwarder issues
Date filed | Issue number | Description |
---|---|---|
2024-10-01 | SPL-263683, SPL-256291 | SessionDetails - Can't encode invalid IP address "localhost", ignoring it |
2024-04-19 | SPL-254532 | UF 9.1.2 Windows Security events stop forwarding when Windows event log service is restarted Workaround: Restart the UF |
2023-12-19 | SPL-248587, SPL-252796, SPL-252797 | Unable to install or upgrade to Splunk Universal Forwarder version 9.1.3 Workaround: Install UF while passing the following feature flag: msiexec.exe /i $SPLUNK_MSI_PACKAGE USE_LOCAL_SYSTEM=1 |
2023-10-31 | SPL-246545, SPL-245807 | Splunk forwarder crashing on AIX when failed to connect to indexers |
2022-08-17 | SPL-228646, SPL-228645 | Restart is needed when AWS access key pairs rotate (w/o grace period) or other S3 config settings for Ingest Actions become invalid |
2022-06-23 | SPL-226019 | Warning appears in the universal forwarder whenever any spl command is run: Warning: Attempting to revert the SPLUNK_HOME ownership Warning: Executing "chown -R splunk /opt/splunkforwarder". This warning is expected and will not affect functionality. |
2022-06-06 | SPL-225379 | Ownership of files mentioned in manifest file is splunk:splunk instead of root:root after enabling boot start as root user for initd Workaround: When changing UF user, manually chown SPLUNK_HOME to the new user, including first time install/upgrade, or manually enable boot-start. |
2022-03-23 | SPL-221239 | System Introspect App fails when universal forwarder is installed at non-admin user |
Troubleshoot the universal forwarder | Fixed issues |
This documentation applies to the following versions of Splunk® Universal Forwarder: 9.1.2
Feedback submitted, thanks!