Deployment Architecture

How do I know the name the forwarder for a particular source?


I have a particular source/sourcetype ; is there a way to know (through SPL) to get the name of the forwarder from which this particular source feed is coming?

Labels (1)
0 Karma


You may not be able to find the forwarder name in all cases.

If the data is being forwarded via universal/heavy forwarder and you're not overriding the 'host' metadata, the host would be your forwarder. (index=x sourcetype=y | stats count by host)

If the data is being forwarder via universal/heavy forwarder but host metadata is being overridden, and you're forwarding your _internal logs from UF/HF to your indexers, you could find the forwarder name in the metrics log (index=_internal sourcetype=Splunkd component=MEtrics group=per_sourcetype_thruput series=yourSourceType | stats count by host)

Get Updates on the Splunk Community!

Index This | Why do they call it hyper text?

November 2023 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

State of Splunk Careers 2023: Career Resilience and the Continued Value of Splunk

For the past three years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

The Great Resilience Quest: 9th Leaderboard Update

The ninth leaderboard update (11.9-11.22) for The Great Resilience Quest is out >> Kudos to all the ...