<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forwarder Monitoring is disabled. in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Forwarder-Monitoring-is-disabled/m-p/625481#M14915</link>
    <description>&lt;P&gt;I can't say I've seen the MC consume a lot of resources.&amp;nbsp; The warning you cite may not apply in your environment.&amp;nbsp; Do you have many forwarders?&lt;/P&gt;</description>
    <pubDate>Thu, 29 Dec 2022 15:45:43 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2022-12-29T15:45:43Z</dc:date>
    <item>
      <title>Forwarder Monitoring is disabled.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Forwarder-Monitoring-is-disabled/m-p/625480#M14914</link>
      <description>&lt;P&gt;On a Windows Server when I go to Settings \ Monitoring Console and launch it, there is a Menu item called: Forwarders: Instance which appears not to be configured and when I try to run setup I get this warning about it effecting performance, so my question is, are any of you running this feature?&lt;/P&gt;&lt;H2&gt;Forwarder Monitoring Setup&lt;/H2&gt;&lt;DIV class=""&gt;&lt;P data-unlink="true"&gt;Forwarder monitoring dashboards provide information on forwarder activity and throughput. If you turn on forwarder monitoring, Splunk Enterprise enables a scheduled search named&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;"DMC Forwarder - Build Asset Table"&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;that relies on internal network input metrics that your indexers record. &lt;FONT color="#FF0000"&gt;If you have many forwarders, this search can significantly affect the search workload of the indexers.&lt;/FONT&gt;&lt;/P&gt;&lt;P data-unlink="true"&gt;To mitigate the cost of this search, increase the data collection interval so that the search runs less frequently.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Learn More&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;H1&gt;Forwarders: Instance&lt;/H1&gt;&lt;H3&gt;Forwarder Monitoring is&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;disabled&lt;/STRONG&gt;. Please go to the&lt;SPAN&gt;&amp;nbsp;setup&amp;nbsp;&lt;/SPAN&gt;page to enable it.&lt;/H3&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Dec 2022 14:59:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Forwarder-Monitoring-is-disabled/m-p/625480#M14914</guid>
      <dc:creator>Gregski11</dc:creator>
      <dc:date>2022-12-29T14:59:03Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder Monitoring is disabled.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Forwarder-Monitoring-is-disabled/m-p/625481#M14915</link>
      <description>&lt;P&gt;I can't say I've seen the MC consume a lot of resources.&amp;nbsp; The warning you cite may not apply in your environment.&amp;nbsp; Do you have many forwarders?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Dec 2022 15:45:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Forwarder-Monitoring-is-disabled/m-p/625481#M14915</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-12-29T15:45:43Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder Monitoring is disabled.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Forwarder-Monitoring-is-disabled/m-p/625536#M14922</link>
      <description>&lt;P&gt;Rich thank you for offering to help, we have two Deployment servers one is for our servers and so over 500 Windows and Linux servers forward to a dozen Indexers&lt;BR /&gt;&lt;BR /&gt;in addition to that Deployment server we have another Deployment server dedicated to all our workstations so another 500 plus Windows workstation machines forward to the same dozen Indexers&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope this paints a better picture for you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Dec 2022 14:33:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Forwarder-Monitoring-is-disabled/m-p/625536#M14922</guid>
      <dc:creator>Gregski11</dc:creator>
      <dc:date>2022-12-30T14:33:05Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder Monitoring is disabled.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Forwarder-Monitoring-is-disabled/m-p/625552#M14926</link>
      <description>&lt;P&gt;A thousand forwarders shouldn't be a problem for an MC and 16 indexers.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Dec 2022 17:38:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Forwarder-Monitoring-is-disabled/m-p/625552#M14926</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-12-30T17:38:50Z</dc:date>
    </item>
  </channel>
</rss>

