Deployment Architecture

Heavy Forwarders Query

carlosvalcarcel
New Member

I have found different articles that query and return information about universal forwarders. But I am trying to get a list of heavy forwarders that the splunk system has. Does anyone have a simple script that would give me a list of all heavy forwarders. 

Labels (1)
0 Karma

carlosvalcarcel
New Member

unfortunately my logs don't go back long enough. I try the query but since my logs don't go back that far it does not provide me with information. 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If your logs go back far enough to capture when the HFs started then this may get you started.

index=_internal component=ServerRoles "Declared role" 
| stats values(role) as roles by host
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...