Deployment Architecture

How do I know the name the forwarder for a particular source?

zacksoft_wf
Contributor

I have a particular source/sourcetype ; is there a way to know (through SPL) to get the name of the forwarder from which this particular source feed is coming?

Labels (1)
0 Karma

somesoni2
Revered Legend

You may not be able to find the forwarder name in all cases.

If the data is being forwarded via universal/heavy forwarder and you're not overriding the 'host' metadata, the host would be your forwarder. (index=x sourcetype=y | stats count by host)

If the data is being forwarder via universal/heavy forwarder but host metadata is being overridden, and you're forwarding your _internal logs from UF/HF to your indexers, you could find the forwarder name in the metrics log (index=_internal sourcetype=Splunkd component=MEtrics group=per_sourcetype_thruput series=yourSourceType | stats count by host)

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...