Getting Data In

Detect gaps in Windows Universal forwarder eventstrem

coenvandijk
Observer

Hello,

We have Splunk 6 running with Universal forarders on all our Windows servers. The forwarders are used to transfer,a subsect as configured in inputs.conf of the Windows TA, to the indexers (a cluster of 2 indexers) How can I see if there have been gaps in the data forwarderd to the indexers?

Thanks in advance!
Coen

Tags (1)
0 Karma

nickhills
Ultra Champion

Take a look at MetaWoot https://splunkbase.splunk.com/app/2949/
It will give you a high degree of confidence in which of your sources are (or are not) working!

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Deprecation of Splunk Observability Kubernetes “Classic Navigator” UI starting ...

Access to Splunk Observability Kubernetes “Classic Navigator” UI will no longer be available starting January ...

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...