<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to ensure we are receiving data from all UF? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-ensure-we-are-receiving-data-from-all-UF/m-p/625716#M14954</link>
    <description>&lt;P&gt;Do *what* exactly using a script?&amp;nbsp; What do you mean by "script"?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can click on the magnifying glass icon in the MC's Forwarder dashboard panels to see the SPL that is used to populate that panel.&amp;nbsp; Then you can copy that SPL to use in your own query.&lt;/P&gt;</description>
    <pubDate>Tue, 03 Jan 2023 14:20:05 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2023-01-03T14:20:05Z</dc:date>
    <item>
      <title>How to ensure we are receiving data from all UF?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-ensure-we-are-receiving-data-from-all-UF/m-p/625629#M14943</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;How can we find out the list of universal forwarders sending data to Splunk?&lt;/P&gt;&lt;P&gt;Also, how do we ensure that all the UF that have been configured are sending data to Splunk?&lt;/P&gt;&lt;P&gt;Thank you so much in advance&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jan 2023 15:59:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-ensure-we-are-receiving-data-from-all-UF/m-p/625629#M14943</guid>
      <dc:creator>izzie123</dc:creator>
      <dc:date>2023-01-02T15:59:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to ensure we are receiving data from all UF?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-ensure-we-are-receiving-data-from-all-UF/m-p/625649#M14948</link>
      <description>&lt;P&gt;The Monitoring Console will have a list of UFs if you've enabled forwarder monitoring.&amp;nbsp; You also can get a list of UFs from the Deployment Server.&lt;/P&gt;&lt;P&gt;The TrackMe app (&lt;A href="https://splunkbase.splunk.com/app/4621" target="_blank"&gt;https://splunkbase.splunk.com/app/4621&lt;/A&gt;) can help you see which UFs are not sending data.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2023 01:08:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-ensure-we-are-receiving-data-from-all-UF/m-p/625649#M14948</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-01-03T01:08:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to ensure we are receiving data from all UF?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-ensure-we-are-receiving-data-from-all-UF/m-p/625651#M14950</link>
      <description>&lt;P&gt;Thank you for your answer, it helped.&lt;/P&gt;&lt;P&gt;Is there any way we can do it inline using a script?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2023 03:58:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-ensure-we-are-receiving-data-from-all-UF/m-p/625651#M14950</guid>
      <dc:creator>izzie123</dc:creator>
      <dc:date>2023-01-03T03:58:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to ensure we are receiving data from all UF?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-ensure-we-are-receiving-data-from-all-UF/m-p/625716#M14954</link>
      <description>&lt;P&gt;Do *what* exactly using a script?&amp;nbsp; What do you mean by "script"?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can click on the magnifying glass icon in the MC's Forwarder dashboard panels to see the SPL that is used to populate that panel.&amp;nbsp; Then you can copy that SPL to use in your own query.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2023 14:20:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-ensure-we-are-receiving-data-from-all-UF/m-p/625716#M14954</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-01-03T14:20:05Z</dc:date>
    </item>
  </channel>
</rss>

