Getting Data In

DMC and dual purpose Splunk server

pwilliams_splun
Splunk Employee
Splunk Employee

I have an indexer and universal forwarder on the same server. The reason for this is that the connection from the indexer to an upstream indexer loses connectivity due to the type of connection and, per the Splunk product team, the indexer will not only stop forwarding when the connection is lost, but also stop indexing. This has been confirmed with the product team as expected behavior per design.

The DMC is picking up the indexer and all other forwarders, but not the forwarder on the same instance as the indexer. The UF's internal logs are, of course, being ingested. Is DMC unable to see the instances individually? Is there any way to configure the UF or the DMC to see this invisible forwarder?

Tags (3)
0 Karma

gjanders
SplunkTrust
SplunkTrust

The monitoring console monitors any search peer, a search peer can be any Splunk enterprise instance.

A universal forwarder cannot be a search peer, however you can enable Forwarder Monitoring this will collect some data on the universal forwarders. Monitoring a universal forwarder through this console is not the same as monitoring an enterprise instance.

There are panels (under Forwarders in 6.5.2) of the monitoring console that relate to universal forwarders that you can use once you enable the forwarder monitoring...

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Unlocking Unified Insights: New Gigamon Federated Search App for Splunk

In today’s data-heavy environment, organizations are caught in a data distribution dilemma. As data volumes ...

GA: New Data Management App in Splunk Platform

Streamlining Data Management: Introducing a unified experience in Splunk Managing data at scale shouldn’t feel ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...