Deployment Architecture

Heavy Forwarders Query

carlosvalcarcel
New Member

I have found different articles that query and return information about universal forwarders. But I am trying to get a list of heavy forwarders that the splunk system has. Does anyone have a simple script that would give me a list of all heavy forwarders. 

Labels (1)
0 Karma

carlosvalcarcel
New Member

unfortunately my logs don't go back long enough. I try the query but since my logs don't go back that far it does not provide me with information. 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If your logs go back far enough to capture when the HFs started then this may get you started.

index=_internal component=ServerRoles "Declared role" 
| stats values(role) as roles by host
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...