<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: forwarder troubleshoot  dashboard in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/forwarder-troubleshoot-dashboard/m-p/708291#M57965</link>
    <description>Here is the other one &lt;A href="https://conf.splunk.com/files/2021/slides/PLA1410C.pdf" target="_blank"&gt;https://conf.splunk.com/files/2021/slides/PLA1410C.pdf&lt;/A&gt;</description>
    <pubDate>Wed, 08 Jan 2025 19:55:41 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2025-01-08T19:55:41Z</dc:date>
    <item>
      <title>forwarder troubleshoot  dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/forwarder-troubleshoot-dashboard/m-p/707762#M57914</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I’m working on creating a Splunk troubleshooting Dashboard for our internal team, who we are new to Splunk, to troubleshoot forwarder issues—specifically cases where no data is being received. I’d like to know the possible ways to troubleshoot forwarders when data is missing or for other related issues. Are there any existing dashboards I could use as a reference? also, what are the key metrics and internal index REST calls that I should focus on to cover all aspects of forwarder troubleshooting?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;#forwarder #troubleshoot #dashboard&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Dec 2024 03:28:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/forwarder-troubleshoot-dashboard/m-p/707762#M57914</guid>
      <dc:creator>Naa_Win</dc:creator>
      <dc:date>2024-12-31T03:28:12Z</dc:date>
    </item>
    <item>
      <title>Re: forwarder troubleshoot  dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/forwarder-troubleshoot-dashboard/m-p/707765#M57915</link>
      <description>&lt;P&gt;There are few stuff that will be useful:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;You can use &lt;STRONG&gt;&lt;STRONG&gt;Monitoring Console's alert and dashboard&lt;/STRONG&gt;&lt;/STRONG&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;STRONG&gt;Dashboard -&amp;gt; Splunk Settings &amp;gt; Monitoring Console &amp;gt; Forwarders: Deployment&lt;/STRONG&gt;&lt;/STRONG&gt;
&lt;UL&gt;
&lt;LI&gt;If setup has not done, then do the setup first (it will give you link to setup)&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;STRONG&gt;Alert -&amp;gt; Splunk Settings &amp;gt; Searches Reports &amp;amp; Alerts&lt;/STRONG&gt;&lt;/STRONG&gt;
&lt;UL&gt;
&lt;LI&gt;Select App as Monitoring Console&lt;/LI&gt;
&lt;LI&gt;Select Owner as All&lt;/LI&gt;
&lt;LI&gt;And search for Missing Forwarder&lt;/LI&gt;
&lt;LI&gt;Enable the alert -&amp;gt; "DMC Alert - Missing forwarders" and add your email to receive alerts on the email&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;There is one more &lt;STRONG&gt;search&lt;/STRONG&gt; you can run to see what data forwarder is sending:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;| tstats count where index=* host="&amp;lt;forwarder-host-name&amp;gt;" by index, sourcetype &lt;/LI-CODE&gt;
&lt;P&gt;I hope this helps!!! Kindly upvote!!!&lt;/P&gt;</description>
      <pubDate>Tue, 31 Dec 2024 15:06:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/forwarder-troubleshoot-dashboard/m-p/707765#M57915</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2024-12-31T15:06:58Z</dc:date>
    </item>
    <item>
      <title>Re: forwarder troubleshoot  dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/forwarder-troubleshoot-dashboard/m-p/707772#M57916</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/258179"&gt;@Naa_Win&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;in all my projects I create a custom app containing dashboards to monitor infrastrcuture, with special attention to:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;fissing data sources,&lt;/LI&gt;&lt;LI&gt;missing hosts,&lt;/LI&gt;&lt;LI&gt;queues issues.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 31 Dec 2024 07:44:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/forwarder-troubleshoot-dashboard/m-p/707772#M57916</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-12-31T07:44:59Z</dc:date>
    </item>
    <item>
      <title>Re: forwarder troubleshoot  dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/forwarder-troubleshoot-dashboard/m-p/707782#M57917</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;here is one conf talk, How to find ingesting issues&amp;nbsp;&lt;SPAN&gt;&lt;A href="https://conf.splunk.com/files/2019/slides/FN1570.pdf" target="_blank"&gt;https://conf.splunk.com/files/2019/slides/FN1570.pdf&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;There are many apps in splunkbase which helps you to find that kind of issues.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also there are some conf presentations about this, but I cannot found those now &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;r. Ismo&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Dec 2024 09:02:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/forwarder-troubleshoot-dashboard/m-p/707782#M57917</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-12-31T09:02:33Z</dc:date>
    </item>
    <item>
      <title>Re: forwarder troubleshoot  dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/forwarder-troubleshoot-dashboard/m-p/707927#M57935</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks for the reply, is that possible to share the app info or share the source code of the dashboards ?&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2025 14:35:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/forwarder-troubleshoot-dashboard/m-p/707927#M57935</guid>
      <dc:creator>Naa_Win</dc:creator>
      <dc:date>2025-01-03T14:35:12Z</dc:date>
    </item>
    <item>
      <title>Re: forwarder troubleshoot  dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/forwarder-troubleshoot-dashboard/m-p/707928#M57936</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/93915"&gt;@VatsalJagani&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks for the info, Yes we have those DMC enabled but the problem is as we are new to Splunk we had given only limited access for now to SH. So we wanted to create some dashboards to look with in the internal logs to detect the issues. I would like to start with the Universal Forwarder first.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2025 14:38:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/forwarder-troubleshoot-dashboard/m-p/707928#M57936</guid>
      <dc:creator>Naa_Win</dc:creator>
      <dc:date>2025-01-03T14:38:04Z</dc:date>
    </item>
    <item>
      <title>Re: forwarder troubleshoot  dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/forwarder-troubleshoot-dashboard/m-p/707938#M57937</link>
      <description>&lt;P&gt;That's why I suggested to look into DMC which has many searches. If you write those searches yourself it will take a lot of time. DMC will give those pre-built searches.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, if you don't have access to DMC in your environment, you can just install Splunk on your local laptop and use that to get searches.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To get the searches, you can open any panel in any panel, by clicking on the bottom-left "Open in search".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps!!!&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2025 15:35:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/forwarder-troubleshoot-dashboard/m-p/707938#M57937</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2025-01-03T15:35:16Z</dc:date>
    </item>
    <item>
      <title>Re: forwarder troubleshoot  dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/forwarder-troubleshoot-dashboard/m-p/707996#M57938</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/258179"&gt;@Naa_Win&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;the dashboards depend on what you need:&lt;/P&gt;&lt;P&gt;if you need to see the hosts that sent logs in the last 30 days but not in the last hour, you can run:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| tstats count WHERE index=_internal earliest=-30d latest=now BY _time host
| where _time&amp;lt;now()-3600
| stats latest(_time) AS _time BY host&lt;/LI-CODE&gt;&lt;P&gt;Then you can display the blocked queues and the status of queues using the searches that I shared at&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/How-do-we-know-whether-typing-queues-are-blocked-or-not/m-p/586347" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/How-do-we-know-whether-typing-queues-are-blocked-or-not/m-p/586347&lt;/A&gt;&lt;/P&gt;&lt;P&gt;and so on.&lt;/P&gt;&lt;P&gt;As I said they depend on what you need to display.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sat, 04 Jan 2025 09:05:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/forwarder-troubleshoot-dashboard/m-p/707996#M57938</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-01-04T09:05:52Z</dc:date>
    </item>
    <item>
      <title>Re: forwarder troubleshoot  dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/forwarder-troubleshoot-dashboard/m-p/708291#M57965</link>
      <description>Here is the other one &lt;A href="https://conf.splunk.com/files/2021/slides/PLA1410C.pdf" target="_blank"&gt;https://conf.splunk.com/files/2021/slides/PLA1410C.pdf&lt;/A&gt;</description>
      <pubDate>Wed, 08 Jan 2025 19:55:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/forwarder-troubleshoot-dashboard/m-p/708291#M57965</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-01-08T19:55:41Z</dc:date>
    </item>
  </channel>
</rss>

