Deployment Architecture

How do I know the name the forwarder for a particular source?

zacksoft_wf
Contributor

I have a particular source/sourcetype ; is there a way to know (through SPL) to get the name of the forwarder from which this particular source feed is coming?

Labels (1)
0 Karma

somesoni2
Revered Legend

You may not be able to find the forwarder name in all cases.

If the data is being forwarded via universal/heavy forwarder and you're not overriding the 'host' metadata, the host would be your forwarder. (index=x sourcetype=y | stats count by host)

If the data is being forwarder via universal/heavy forwarder but host metadata is being overridden, and you're forwarding your _internal logs from UF/HF to your indexers, you could find the forwarder name in the metrics log (index=_internal sourcetype=Splunkd component=MEtrics group=per_sourcetype_thruput series=yourSourceType | stats count by host)

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...