Deployment Architecture

How do I know the name the forwarder for a particular source?

zacksoft_wf
Contributor

I have a particular source/sourcetype ; is there a way to know (through SPL) to get the name of the forwarder from which this particular source feed is coming?

Labels (1)
0 Karma

somesoni2
Revered Legend

You may not be able to find the forwarder name in all cases.

If the data is being forwarded via universal/heavy forwarder and you're not overriding the 'host' metadata, the host would be your forwarder. (index=x sourcetype=y | stats count by host)

If the data is being forwarder via universal/heavy forwarder but host metadata is being overridden, and you're forwarding your _internal logs from UF/HF to your indexers, you could find the forwarder name in the metrics log (index=_internal sourcetype=Splunkd component=MEtrics group=per_sourcetype_thruput series=yourSourceType | stats count by host)

Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...