Hi,
I'm trying to write a query to see whether a Splunk agent status(forwarders) is running or stopped(forcefully stopped).So by doing it i can compare the result from AWS app and agent data to list the discrepancies.
some related questions with nice answers here:
https://answers.splunk.com/answers/798/how-do-i-tell-if-a-forwarder-is-down.html
https://answers.splunk.com/answers/379013/alert-if-a-forwarder-service-stops.html