<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Without have access to the universal forwarder, can I check whether it is sending data to the heavy forwarder? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Without-have-access-to-the-universal-forwarder-can-I-check/m-p/408254#M72383</link>
    <description>&lt;P&gt;Thanks for your answer, I was not sure yesterday whether deployment server can manage the data as well or just apps, did some more research and found my answer.&lt;/P&gt;

&lt;P&gt;Thanks for your support.&lt;BR /&gt;
Regards&lt;BR /&gt;
Rohit&lt;/P&gt;</description>
    <pubDate>Fri, 05 Oct 2018 00:06:20 GMT</pubDate>
    <dc:creator>Sharmarohit1234</dc:creator>
    <dc:date>2018-10-05T00:06:20Z</dc:date>
    <item>
      <title>Without have access to the universal forwarder, can I check whether it is sending data to the heavy forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Without-have-access-to-the-universal-forwarder-can-I-check/m-p/408251#M72380</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;I am relatively new to Splunk, In my environment we are using deployment server to manage the deployment apps on universal forwarders.&lt;/P&gt;

&lt;P&gt;During the installation of universal forwarders, we specify the deployment server in deployment.conf.&lt;/P&gt;

&lt;P&gt;But we have not mentioned anything about forwarding the data to the heavy forwarder (HF).&lt;/P&gt;

&lt;P&gt;On the web interface of our heavy forwarders, under forwarding and receiving, I cannot see any configuration set up.&lt;/P&gt;

&lt;P&gt;How can I check whether universal forwarders are sending data to HF? Are indexers or data getting managed by the deployment server?&lt;/P&gt;

&lt;P&gt;I don't have access to the universal forwarders as these are managed by some different team.&lt;/P&gt;

&lt;P&gt;So I have to check the configuration within the HF, Indexer or deployment servers.&lt;/P&gt;

&lt;P&gt;Regards&lt;BR /&gt;
Rohit&lt;/P&gt;</description>
      <pubDate>Thu, 04 Oct 2018 04:42:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Without-have-access-to-the-universal-forwarder-can-I-check/m-p/408251#M72380</guid>
      <dc:creator>Sharmarohit1234</dc:creator>
      <dc:date>2018-10-04T04:42:47Z</dc:date>
    </item>
    <item>
      <title>Re: Without have access to the universal forwarder, can I check whether it is sending data to the heavy forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Without-have-access-to-the-universal-forwarder-can-I-check/m-p/408252#M72381</link>
      <description>&lt;P&gt;You need to open up that port for sending data into your Deployment server. &lt;BR /&gt;
If you have any FW on your env, you need to probably open that up too&lt;/P&gt;</description>
      <pubDate>Thu, 04 Oct 2018 05:42:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Without-have-access-to-the-universal-forwarder-can-I-check/m-p/408252#M72381</guid>
      <dc:creator>iamarkaprabha</dc:creator>
      <dc:date>2018-10-04T05:42:38Z</dc:date>
    </item>
    <item>
      <title>Re: Without have access to the universal forwarder, can I check whether it is sending data to the heavy forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Without-have-access-to-the-universal-forwarder-can-I-check/m-p/408253#M72382</link>
      <description>&lt;P&gt;Hi @Sharmarohit1234,&lt;/P&gt;

&lt;P&gt;You can use below query to check which servers (Universal Forwarders, Heavy Forwarders, Search Heads OR any other Splunk servers) are sending data to Indexers.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal host=INDEXER_SERVERNAME source=*metrics.log* group=tcpin_connections | dedup hostname | table _time hostname os arch version sourceIp destPort fwdType ssl
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;In above query if you change &lt;CODE&gt;INDEXER_SERVERNAME&lt;/CODE&gt; with &lt;CODE&gt;HeavyForwarder_SERVERNAME&lt;/CODE&gt; you will able to figure out if any universal forwarders are sending data to Heavy Forwarder or not.&lt;/P&gt;

&lt;P&gt;I didn't get your question &lt;CODE&gt;Data is getting managed by Deployment server?&lt;/CODE&gt;, Deployment server will deploy configuration to UF, Heavy Forwarders etc. but it will not manage any data.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Oct 2018 09:59:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Without-have-access-to-the-universal-forwarder-can-I-check/m-p/408253#M72382</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2018-10-04T09:59:03Z</dc:date>
    </item>
    <item>
      <title>Re: Without have access to the universal forwarder, can I check whether it is sending data to the heavy forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Without-have-access-to-the-universal-forwarder-can-I-check/m-p/408254#M72383</link>
      <description>&lt;P&gt;Thanks for your answer, I was not sure yesterday whether deployment server can manage the data as well or just apps, did some more research and found my answer.&lt;/P&gt;

&lt;P&gt;Thanks for your support.&lt;BR /&gt;
Regards&lt;BR /&gt;
Rohit&lt;/P&gt;</description>
      <pubDate>Fri, 05 Oct 2018 00:06:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Without-have-access-to-the-universal-forwarder-can-I-check/m-p/408254#M72383</guid>
      <dc:creator>Sharmarohit1234</dc:creator>
      <dc:date>2018-10-05T00:06:20Z</dc:date>
    </item>
  </channel>
</rss>

