<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Heavy Forwarder iNSTALLED OR NOT in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Heavy-Forwarder-iNSTALLED-OR-NOT/m-p/543558#M7229</link>
    <description>&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;I&amp;nbsp; have asked to Add the new Linux HFs to the forwarding configurations and ensure that logs are passing through them&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;how to verify the condition is met or not&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 12 Mar 2021 15:10:42 GMT</pubDate>
    <dc:creator>umeshcreddy</dc:creator>
    <dc:date>2021-03-12T15:10:42Z</dc:date>
    <item>
      <title>Heavy Forwarder iNSTALLED OR NOT</title>
      <link>https://community.splunk.com/t5/Installation/Heavy-Forwarder-iNSTALLED-OR-NOT/m-p/543558#M7229</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;I&amp;nbsp; have asked to Add the new Linux HFs to the forwarding configurations and ensure that logs are passing through them&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;how to verify the condition is met or not&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Mar 2021 15:10:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Heavy-Forwarder-iNSTALLED-OR-NOT/m-p/543558#M7229</guid>
      <dc:creator>umeshcreddy</dc:creator>
      <dc:date>2021-03-12T15:10:42Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarder iNSTALLED OR NOT</title>
      <link>https://community.splunk.com/t5/Installation/Heavy-Forwarder-iNSTALLED-OR-NOT/m-p/543562#M7230</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232426"&gt;@umeshcreddy&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;let me understand:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;do you want to know if you're receiving logs from that HF&lt;/LI&gt;&lt;LI&gt;or do you want to know if the logs passing through the HF arrive to the Indexers?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;in the first case run on Search Heads &amp;nbsp;the following search:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;(index=_internal OR index=*) host=HF_hostname&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;If instead your HF is a concentrator and you want to know if logs are passing, list the hosts that are sending logs anche check if there are the correct list of hosts with a simple search on Search Heads:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal OR index=*
| stats count BY host&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 12 Mar 2021 16:41:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Heavy-Forwarder-iNSTALLED-OR-NOT/m-p/543562#M7230</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-03-12T16:41:44Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarder iNSTALLED OR NOT</title>
      <link>https://community.splunk.com/t5/Installation/Heavy-Forwarder-iNSTALLED-OR-NOT/m-p/543616#M7233</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp; cant we check in the deployment sever in the forwarder management for the HF_hostname whether deployed or not.&amp;nbsp; I have this doubt can you please confirm&lt;/P&gt;</description>
      <pubDate>Sat, 13 Mar 2021 07:13:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Heavy-Forwarder-iNSTALLED-OR-NOT/m-p/543616#M7233</guid>
      <dc:creator>umeshcreddy</dc:creator>
      <dc:date>2021-03-13T07:13:54Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy Forwarder iNSTALLED OR NOT</title>
      <link>https://community.splunk.com/t5/Installation/Heavy-Forwarder-iNSTALLED-OR-NOT/m-p/543663#M7235</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232426"&gt;@umeshcreddy&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;to check if HF was deployed by Deployment Server is a different thing: it's not relevant Ds to understand if an HF is logging or not.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S. Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Mar 2021 17:36:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Heavy-Forwarder-iNSTALLED-OR-NOT/m-p/543663#M7235</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-03-13T17:36:58Z</dc:date>
    </item>
  </channel>
</rss>

