<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forwarded UDP - Check which forwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Forwarded-UDP-Check-which-forwarder/m-p/87353#M18116</link>
    <description>&lt;P&gt;Thanks for the response, however:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;Running netstat on each box doesn't scale very well, as I don't know which host it is on&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;The metadata command appears to return nothing more than: firstTime; lastTime; recentTime; source; totalCount; type&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
    <pubDate>Tue, 09 Apr 2013 12:09:31 GMT</pubDate>
    <dc:creator>SplunkFu</dc:creator>
    <dc:date>2013-04-09T12:09:31Z</dc:date>
    <item>
      <title>Forwarded UDP - Check which forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarded-UDP-Check-which-forwarder/m-p/87351#M18114</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;

&lt;P&gt;I'm hoping this is a simple question...&lt;/P&gt;

&lt;P&gt;We have 50+ forwarders, and I'm trying to locate the forwarder that passes Syslog traffic to our Indexer, but I can't seem to find the information from Splunk's perspective, is there any where to find this information without looking at the configuration on the source?&lt;/P&gt;

&lt;P&gt;Thanks and best regards.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2013 13:09:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarded-UDP-Check-which-forwarder/m-p/87351#M18114</guid>
      <dc:creator>SplunkFu</dc:creator>
      <dc:date>2013-04-08T13:09:47Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarded UDP - Check which forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarded-UDP-Check-which-forwarder/m-p/87352#M18115</link>
      <description>&lt;P&gt;I would suggest running:&lt;/P&gt;

&lt;P&gt;netstat -nat | grep 514&lt;/P&gt;

&lt;P&gt;If you know the índex which is receiving the syslog data you can query the metadata:&lt;/P&gt;

&lt;P&gt;| metadata type=sources índex="yourindeX"&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2013 14:24:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarded-UDP-Check-which-forwarder/m-p/87352#M18115</guid>
      <dc:creator>krugger</dc:creator>
      <dc:date>2013-04-08T14:24:58Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarded UDP - Check which forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarded-UDP-Check-which-forwarder/m-p/87353#M18116</link>
      <description>&lt;P&gt;Thanks for the response, however:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;Running netstat on each box doesn't scale very well, as I don't know which host it is on&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;The metadata command appears to return nothing more than: firstTime; lastTime; recentTime; source; totalCount; type&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Tue, 09 Apr 2013 12:09:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarded-UDP-Check-which-forwarder/m-p/87353#M18116</guid>
      <dc:creator>SplunkFu</dc:creator>
      <dc:date>2013-04-09T12:09:31Z</dc:date>
    </item>
  </channel>
</rss>

