Getting Data In

Can I see if a network interface is left ON?

splunktrainingu
Communicator

I have an Enclave server that already forwards logs to my indexer. We installed a network interface that should remain turned off unless we are upgrading/patching the server. Is there a way to see if the Network interface was left ON?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If the state of the network interface is in Splunk, then you can search for it to see if it's on or not.

---
If this reply helps you, Karma would be appreciated.
0 Karma

splunktrainingu
Communicator

How can I see if the state of the network interface is in splunk? What would I be searching for?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I have to defer to a local data expert (hopefully, that's you). Try searching for the interface name.

---
If this reply helps you, Karma would be appreciated.
0 Karma

splunktrainingu
Communicator

I am seeing the perfmon interface logs but not from all the hosts only some.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If you see the network interface for the Enclave server then you should be all set. Otherwise, you have some onboarding or troubleshooting to do.

---
If this reply helps you, Karma would be appreciated.
0 Karma

splunktrainingu
Communicator

Looks like I have a lot of onboarding to do I am able to see my forwarders but I am not getting logs for some of the devices.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Splunk Observability Metrics Cost Optimization

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...