<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: find out which Splunk server received the event. in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/find-out-which-Splunk-server-received-the-event/m-p/537090#M4762</link>
    <description>&lt;P&gt;Forwarding is transparent so there's no indication of where an event was forwarded from (unless you've taken actions to add something).&lt;/P&gt;&lt;P&gt;Check your search heads and indexers for inputs.conf files and remove any TCP or UDP inputs.&lt;/P&gt;</description>
    <pubDate>Mon, 25 Jan 2021 18:28:36 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-01-25T18:28:36Z</dc:date>
    <item>
      <title>find out which Splunk server received the event.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/find-out-which-Splunk-server-received-the-event/m-p/536986#M4757</link>
      <description>&lt;P&gt;I all as an architect sometimes I find myself in environment where the inputs are misconfigured and splunk servers are receiving traffic directly. For example the search head and indexer receiving traffic directly even if a syslog server/HF is present in the environment. Is there a search with which I can find out each source type and which Splunk &amp;nbsp;server is receiving the logs and forwarding it to the indexer layer. This will really help in resolving issues.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 06:30:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/find-out-which-Splunk-server-received-the-event/m-p/536986#M4757</guid>
      <dc:creator>rabrahaham</dc:creator>
      <dc:date>2021-01-25T06:30:04Z</dc:date>
    </item>
    <item>
      <title>Re: find out which Splunk server received the event.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/find-out-which-Splunk-server-received-the-event/m-p/537090#M4762</link>
      <description>&lt;P&gt;Forwarding is transparent so there's no indication of where an event was forwarded from (unless you've taken actions to add something).&lt;/P&gt;&lt;P&gt;Check your search heads and indexers for inputs.conf files and remove any TCP or UDP inputs.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 18:28:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/find-out-which-Splunk-server-received-the-event/m-p/537090#M4762</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-01-25T18:28:36Z</dc:date>
    </item>
    <item>
      <title>Re: find out which Splunk server received the event.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/find-out-which-Splunk-server-received-the-event/m-p/537118#M4763</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/226295"&gt;@rabrahaham&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You can find your forwarders destinations using below search, normally you should not see an address other than indexer or heavy forwarder.&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal component=TcpOutputProc 
| stats count by idx&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 20:27:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/find-out-which-Splunk-server-received-the-event/m-p/537118#M4763</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-01-25T20:27:21Z</dc:date>
    </item>
  </channel>
</rss>

