Getting Data In

DMC and dual purpose Splunk server

pwilliams_splun
Splunk Employee
Splunk Employee

I have an indexer and universal forwarder on the same server. The reason for this is that the connection from the indexer to an upstream indexer loses connectivity due to the type of connection and, per the Splunk product team, the indexer will not only stop forwarding when the connection is lost, but also stop indexing. This has been confirmed with the product team as expected behavior per design.

The DMC is picking up the indexer and all other forwarders, but not the forwarder on the same instance as the indexer. The UF's internal logs are, of course, being ingested. Is DMC unable to see the instances individually? Is there any way to configure the UF or the DMC to see this invisible forwarder?

Tags (3)
0 Karma

gjanders
SplunkTrust
SplunkTrust

The monitoring console monitors any search peer, a search peer can be any Splunk enterprise instance.

A universal forwarder cannot be a search peer, however you can enable Forwarder Monitoring this will collect some data on the universal forwarders. Monitoring a universal forwarder through this console is not the same as monitoring an enterprise instance.

There are panels (under Forwarders in 6.5.2) of the monitoring console that relate to universal forwarders that you can use once you enable the forwarder monitoring...

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...