<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to get Splunk UF versions in Intermediate forwarder set up? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Splunk-UF-versions-in-Intermediate-forwarder-set-up/m-p/608669#M105589</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;FYI&lt;/P&gt;&lt;P&gt;limits.conf&lt;BR /&gt;[metrics:tcpin_connections]&lt;BR /&gt;aggregate_metrics = true&lt;/P&gt;&lt;P&gt;this setting will aggregate the data being received on the Intermediate forwarders so does not report the individual servers.&lt;/P&gt;</description>
    <pubDate>Mon, 08 Aug 2022 10:46:23 GMT</pubDate>
    <dc:creator>dmcintosh1972</dc:creator>
    <dc:date>2022-08-08T10:46:23Z</dc:date>
    <item>
      <title>How to get Splunk UF versions in Intermediate forwarder set up?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Splunk-UF-versions-in-Intermediate-forwarder-set-up/m-p/607787#M105495</link>
      <description>&lt;P&gt;Hi can anyone think of a way to get Splunk versions reported from universal forwarders when in a Intermediate forwarder environment.&lt;/P&gt;
&lt;P&gt;I have tried searches like&amp;nbsp;&lt;/P&gt;
&lt;P&gt;index=_internal sourcetype=splunkd group=tcpin_connections&lt;BR /&gt;but it only returns the agent version of the intermediate layer, not the UF versions behind it.&lt;/P&gt;
&lt;P&gt;Are there any commands that can be deployed via to each UF to collect that information?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Aug 2022 19:45:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Splunk-UF-versions-in-Intermediate-forwarder-set-up/m-p/607787#M105495</guid>
      <dc:creator>dmcintosh1972</dc:creator>
      <dc:date>2022-08-01T19:45:17Z</dc:date>
    </item>
    <item>
      <title>Re: Get Splunk UF versions in Intermediate forwarder set up</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Splunk-UF-versions-in-Intermediate-forwarder-set-up/m-p/607802#M105497</link>
      <description>&lt;P&gt;The intermediate forwarders should be logging the tcpin_connection events they get from UFs (at least if they're heavy forwarders).&amp;nbsp; Check that they are forwarding their logs&lt;/P&gt;</description>
      <pubDate>Mon, 01 Aug 2022 16:54:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Splunk-UF-versions-in-Intermediate-forwarder-set-up/m-p/607802#M105497</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-08-01T16:54:46Z</dc:date>
    </item>
    <item>
      <title>Re: Get Splunk UF versions in Intermediate forwarder set up</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Splunk-UF-versions-in-Intermediate-forwarder-set-up/m-p/607804#M105498</link>
      <description>&lt;P&gt;UFs are reporting their version just like IUFs, just check/add their name to your query.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Aug 2022 17:18:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Splunk-UF-versions-in-Intermediate-forwarder-set-up/m-p/607804#M105498</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-08-01T17:18:43Z</dc:date>
    </item>
    <item>
      <title>Re: Get Splunk UF versions in Intermediate forwarder set up</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Splunk-UF-versions-in-Intermediate-forwarder-set-up/m-p/607819#M105502</link>
      <description>&lt;P&gt;thanks for your help, not sure if i need to enable something. to log more metrics?&lt;BR /&gt;from UF i only see the group fields per_host_thruput, instance.&lt;/P&gt;&lt;P&gt;The&amp;nbsp;group=tcpin_connections are only logged under my cloud indexers and the hostnames covered are the cloud infrastructure and the IUF's, now other UF servers.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Aug 2022 19:39:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Splunk-UF-versions-in-Intermediate-forwarder-set-up/m-p/607819#M105502</guid>
      <dc:creator>dmcintosh1972</dc:creator>
      <dc:date>2022-08-01T19:39:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to get Splunk UF versions in Intermediate forwarder set up?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Splunk-UF-versions-in-Intermediate-forwarder-set-up/m-p/608669#M105589</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;FYI&lt;/P&gt;&lt;P&gt;limits.conf&lt;BR /&gt;[metrics:tcpin_connections]&lt;BR /&gt;aggregate_metrics = true&lt;/P&gt;&lt;P&gt;this setting will aggregate the data being received on the Intermediate forwarders so does not report the individual servers.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2022 10:46:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-get-Splunk-UF-versions-in-Intermediate-forwarder-set-up/m-p/608669#M105589</guid>
      <dc:creator>dmcintosh1972</dc:creator>
      <dc:date>2022-08-08T10:46:23Z</dc:date>
    </item>
  </channel>
</rss>

