<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help locating what forwarder data is coming from in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Help-locating-what-forwarder-data-is-coming-from/m-p/170185#M34381</link>
    <description>&lt;P&gt;I know what server it's coming from I'm trying to find out if it's some default data from the universal forwarder, from the windows infrastructure app, or from the VMware app we have loaded.&lt;/P&gt;

&lt;P&gt;I dont think it's the vmware app because it splits their sourcetypes into vmware:something...&lt;/P&gt;

&lt;P&gt;So I think it's either the default or the infrastrcture app.&lt;/P&gt;

&lt;P&gt;I have suspicions it's the default forwarder actions, but if that's the case why wouldnt every server i have the forwarder on send perfmon data, unless it's because these 2 are my DCs.&lt;/P&gt;

&lt;P&gt;In any event Im more interested in blocking it.&lt;/P&gt;</description>
    <pubDate>Tue, 05 Aug 2014 13:57:51 GMT</pubDate>
    <dc:creator>jbleich</dc:creator>
    <dc:date>2014-08-05T13:57:51Z</dc:date>
    <item>
      <title>Help locating what forwarder data is coming from</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-locating-what-forwarder-data-is-coming-from/m-p/170181#M34377</link>
      <description>&lt;P&gt;I'm a new splunk user, so be kind &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;I have about 80% of my daily volume coming in what i believe to be un-needed informaton. I cant tell where the data is coming from, all i know is index=main and sourcetype=Perfmon:process&lt;/P&gt;

&lt;P&gt;Now i thought it was the universal forwarders on my DC's, I have 2 of them and pushed out the app via the deployment server and i changed the .conf file to disable Perfmon:process, but apparently that wasnt it...it must be coming from somewhere else.&lt;/P&gt;

&lt;P&gt;Any help would be appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Aug 2014 20:58:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-locating-what-forwarder-data-is-coming-from/m-p/170181#M34377</guid>
      <dc:creator>jbleich</dc:creator>
      <dc:date>2014-08-04T20:58:53Z</dc:date>
    </item>
    <item>
      <title>Re: Help locating what forwarder data is coming from</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-locating-what-forwarder-data-is-coming-from/m-p/170182#M34378</link>
      <description>&lt;P&gt;There should be a field host which should tell you from which server its coming from.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Aug 2014 21:02:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-locating-what-forwarder-data-is-coming-from/m-p/170182#M34378</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-08-04T21:02:06Z</dc:date>
    </item>
    <item>
      <title>Re: Help locating what forwarder data is coming from</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-locating-what-forwarder-data-is-coming-from/m-p/170183#M34379</link>
      <description>&lt;P&gt;somesoni2 has already pointed what you need to check.&lt;/P&gt;

&lt;P&gt;index=main | dedup host | table host&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2014 02:06:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-locating-what-forwarder-data-is-coming-from/m-p/170183#M34379</guid>
      <dc:creator>strive</dc:creator>
      <dc:date>2014-08-05T02:06:31Z</dc:date>
    </item>
    <item>
      <title>Re: Help locating what forwarder data is coming from</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-locating-what-forwarder-data-is-coming-from/m-p/170184#M34380</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
below is the fastest way to get the time and host which is responsible for the data.&lt;/P&gt;

&lt;P&gt;|metadata type=hosts index=*&lt;/P&gt;

&lt;P&gt;It shows you the first and latest received event time and number of events. So try this.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
L&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2014 04:20:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-locating-what-forwarder-data-is-coming-from/m-p/170184#M34380</guid>
      <dc:creator>linu1988</dc:creator>
      <dc:date>2014-08-05T04:20:09Z</dc:date>
    </item>
    <item>
      <title>Re: Help locating what forwarder data is coming from</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-locating-what-forwarder-data-is-coming-from/m-p/170185#M34381</link>
      <description>&lt;P&gt;I know what server it's coming from I'm trying to find out if it's some default data from the universal forwarder, from the windows infrastructure app, or from the VMware app we have loaded.&lt;/P&gt;

&lt;P&gt;I dont think it's the vmware app because it splits their sourcetypes into vmware:something...&lt;/P&gt;

&lt;P&gt;So I think it's either the default or the infrastrcture app.&lt;/P&gt;

&lt;P&gt;I have suspicions it's the default forwarder actions, but if that's the case why wouldnt every server i have the forwarder on send perfmon data, unless it's because these 2 are my DCs.&lt;/P&gt;

&lt;P&gt;In any event Im more interested in blocking it.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2014 13:57:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-locating-what-forwarder-data-is-coming-from/m-p/170185#M34381</guid>
      <dc:creator>jbleich</dc:creator>
      <dc:date>2014-08-05T13:57:51Z</dc:date>
    </item>
  </channel>
</rss>

