<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can I Add selected  heavy forwrders in splunk monitoring console in forwarder section? in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Can-I-Add-selected-heavy-forwrders-in-splunk-monitoring-console/m-p/379739#M3241</link>
    <description>&lt;P&gt;Any other Idea please? anyone?&lt;/P&gt;</description>
    <pubDate>Wed, 13 Feb 2019 11:56:33 GMT</pubDate>
    <dc:creator>splbsm</dc:creator>
    <dc:date>2019-02-13T11:56:33Z</dc:date>
    <item>
      <title>Can I Add selected  heavy forwrders in splunk monitoring console in forwarder section?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Can-I-Add-selected-heavy-forwrders-in-splunk-monitoring-console/m-p/379736#M3238</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;

&lt;P&gt;I want to be able to add only a few selected heavy forwarders in my distributed monitoring console. &lt;BR /&gt;
so basically  I want to use wildcard  (or may be a text file with list of forwarders or something similar ) for hostnames of these HFs and only add these matching HF's in my Monitoring console in forwarder section.. &lt;BR /&gt;
Is this possible in splunk ?&lt;/P&gt;

&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 12 Feb 2019 13:00:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Can-I-Add-selected-heavy-forwrders-in-splunk-monitoring-console/m-p/379736#M3238</guid>
      <dc:creator>splbsm</dc:creator>
      <dc:date>2019-02-12T13:00:08Z</dc:date>
    </item>
    <item>
      <title>Re: Can I Add selected  heavy forwrders in splunk monitoring console in forwarder section?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Can-I-Add-selected-heavy-forwrders-in-splunk-monitoring-console/m-p/379737#M3239</link>
      <description>&lt;P&gt;Hi @splbsm &lt;/P&gt;

&lt;P&gt;If you are a customer that has a few heavy forwarders then it probably means you are large enough that you should consider having a stand-alone monitoring console. With a stand-alone monitoring console you should only add the heavy forwarders you care about as search peers. This way your less important heavy forwarders won't be displayed in the monitoring console. Once a server is defined as a search peer to the monitoring console it will be displayed. You can't filter it using a wildcard.&lt;/P&gt;

&lt;P&gt;All the best.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Feb 2019 19:15:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Can-I-Add-selected-heavy-forwrders-in-splunk-monitoring-console/m-p/379737#M3239</guid>
      <dc:creator>chrisyounger</dc:creator>
      <dc:date>2019-02-12T19:15:13Z</dc:date>
    </item>
    <item>
      <title>Re: Can I Add selected  heavy forwrders in splunk monitoring console in forwarder section?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Can-I-Add-selected-heavy-forwrders-in-splunk-monitoring-console/m-p/379738#M3240</link>
      <description>&lt;P&gt;Thanks for taking time for this post Chris, much appreciated. &lt;/P&gt;

&lt;P&gt;Yes, at the moment I already have these HF's added as indexers. &lt;BR /&gt;
But I'd like to add and see these HF's as HF in monitoring console in the forwarder section. &lt;BR /&gt;
as you already guessed, I can NOT add all UF and HFs there because I have 1000s of UF's.&lt;/P&gt;

&lt;P&gt;So Can I not add only a few select HF's in as HFs in monitoring console under forwarders?&lt;/P&gt;

&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2019 09:02:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Can-I-Add-selected-heavy-forwrders-in-splunk-monitoring-console/m-p/379738#M3240</guid>
      <dc:creator>splbsm</dc:creator>
      <dc:date>2019-02-13T09:02:00Z</dc:date>
    </item>
    <item>
      <title>Re: Can I Add selected  heavy forwrders in splunk monitoring console in forwarder section?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Can-I-Add-selected-heavy-forwrders-in-splunk-monitoring-console/m-p/379739#M3241</link>
      <description>&lt;P&gt;Any other Idea please? anyone?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2019 11:56:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Can-I-Add-selected-heavy-forwrders-in-splunk-monitoring-console/m-p/379739#M3241</guid>
      <dc:creator>splbsm</dc:creator>
      <dc:date>2019-02-13T11:56:33Z</dc:date>
    </item>
    <item>
      <title>Re: Can I Add selected  heavy forwrders in splunk monitoring console in forwarder section?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Can-I-Add-selected-heavy-forwrders-in-splunk-monitoring-console/m-p/379740#M3242</link>
      <description>&lt;P&gt;Any Other Idea please?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2019 12:13:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Can-I-Add-selected-heavy-forwrders-in-splunk-monitoring-console/m-p/379740#M3242</guid>
      <dc:creator>splbsm</dc:creator>
      <dc:date>2019-02-13T12:13:42Z</dc:date>
    </item>
    <item>
      <title>Re: Can I Add selected  heavy forwrders in splunk monitoring console in forwarder section?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Can-I-Add-selected-heavy-forwrders-in-splunk-monitoring-console/m-p/379741#M3243</link>
      <description>&lt;P&gt;You cannot select to have only a few forwarders in the Monitoring Console, as this is depending on having the "full view" of everything going on in your environment.&lt;/P&gt;

&lt;P&gt;But you could go for the following solution:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Add all forwarders to the MC&lt;/LI&gt;
&lt;LI&gt;Use the dmc_forwarder_assets alert &lt;/LI&gt;
&lt;LI&gt;limit the search results to the HFs relevant for you by creating a lookup file &lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;A search could look like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| inputlookup dmc_forwarder_assets
  [|inputlookup your_hf_list.csv | return hostname]
| search status="missing"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This should give you a list of all missing HF out of your selection.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:13:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Can-I-Add-selected-heavy-forwrders-in-splunk-monitoring-console/m-p/379741#M3243</guid>
      <dc:creator>DMohn</dc:creator>
      <dc:date>2020-09-29T23:13:25Z</dc:date>
    </item>
    <item>
      <title>Re: Can I Add selected  heavy forwrders in splunk monitoring console in forwarder section?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Can-I-Add-selected-heavy-forwrders-in-splunk-monitoring-console/m-p/379742#M3244</link>
      <description>&lt;P&gt;You mean "DMC Forwarder - Build Asset Table " Alert please?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2019 14:15:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Can-I-Add-selected-heavy-forwrders-in-splunk-monitoring-console/m-p/379742#M3244</guid>
      <dc:creator>splbsm</dc:creator>
      <dc:date>2019-02-13T14:15:04Z</dc:date>
    </item>
    <item>
      <title>Re: Can I Add selected  heavy forwrders in splunk monitoring console in forwarder section?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Can-I-Add-selected-heavy-forwrders-in-splunk-monitoring-console/m-p/379743#M3245</link>
      <description>&lt;P&gt;Also, I have some 60k UF's. if I add them all , will it not be a huge risk for my MC performance? Please advice.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2019 14:23:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Can-I-Add-selected-heavy-forwrders-in-splunk-monitoring-console/m-p/379743#M3245</guid>
      <dc:creator>splbsm</dc:creator>
      <dc:date>2019-02-13T14:23:15Z</dc:date>
    </item>
    <item>
      <title>Re: Can I Add selected  heavy forwrders in splunk monitoring console in forwarder section?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Can-I-Add-selected-heavy-forwrders-in-splunk-monitoring-console/m-p/379744#M3246</link>
      <description>&lt;P&gt;Start by enableing the forwarder monitoring in the MC with Settings =&amp;gt; Forwarder Monitoring Setup. You can reduce the data colletion interval if you desire.&lt;/P&gt;

&lt;P&gt;This will enable the MC to run internal saved searches, one of which builds the forwarder asset table. This can be accessed in a regular Splunk search with &lt;CODE&gt;| inputlookup dmc_forwarder_assets&lt;/CODE&gt;. From there on you can build your custom alert which will only cover your selected Heavy Forwarders. This is &lt;EM&gt;not&lt;/EM&gt; a built-in MC alert anymore, as the standard alerts will alert for &lt;EM&gt;any&lt;/EM&gt; missing forwarder. So your should leave these alerts turned off.&lt;/P&gt;

&lt;P&gt;And no, this will not be a huge performance risk for your instance &lt;STRONG&gt;if you have sized it accordingly&lt;/STRONG&gt;. Be aware that a MC used for such a large architecture has to be a standalone instance, with no other funcionalities. &lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2019 14:41:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Can-I-Add-selected-heavy-forwrders-in-splunk-monitoring-console/m-p/379744#M3246</guid>
      <dc:creator>DMohn</dc:creator>
      <dc:date>2019-02-13T14:41:17Z</dc:date>
    </item>
    <item>
      <title>Re: Can I Add selected  heavy forwrders in splunk monitoring console in forwarder section?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Can-I-Add-selected-heavy-forwrders-in-splunk-monitoring-console/m-p/379745#M3247</link>
      <description>&lt;P&gt;yes, it is standalone MC. thanks.. &lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2019 14:50:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Can-I-Add-selected-heavy-forwrders-in-splunk-monitoring-console/m-p/379745#M3247</guid>
      <dc:creator>splbsm</dc:creator>
      <dc:date>2019-02-13T14:50:06Z</dc:date>
    </item>
    <item>
      <title>Re: Can I Add selected  heavy forwrders in splunk monitoring console in forwarder section?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Can-I-Add-selected-heavy-forwrders-in-splunk-monitoring-console/m-p/379746#M3248</link>
      <description>&lt;P&gt;If this works for you, could you please mark the answer as accepted, so others will so that there's a solution? Thanks &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Feb 2019 08:26:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Can-I-Add-selected-heavy-forwrders-in-splunk-monitoring-console/m-p/379746#M3248</guid>
      <dc:creator>DMohn</dc:creator>
      <dc:date>2019-02-14T08:26:54Z</dc:date>
    </item>
  </channel>
</rss>

