Getting Data In

Determine The Amount Of Data Forwarded By Splunk Forwarder Over Time X

tehmasp
Engager

Want to know if there is an easy way to check the amount of data a Splunk Forwarder on a box has forwarded to an Indexer over some period of time? Is this data logged somewhere? Is there a Splunk search I can do w/ a 'host' attribute and determine the amount of raw data collected over the search period? Thanks!

Tags (1)
1 Solution

_d_
Splunk Employee
Splunk Employee

Yes, install Deployment Monitor app on Splunk Indexer and you will have access to really useful information/charts/dashboards about all your splunk instances including what you're looking for and more. If you are on Splunk 4.2.3 or later you just have to enable it (as it comes with it).
Otherwise use this link to get it: http://splunk-base.splunk.com/apps/22301/splunk-deployment-monitor

Hope this helps

> please upvote and accept answer if you find it useful - thanks!

View solution in original post

tehmasp
Engager

Ah, right. I have this installed but don't use it nearly often. Thanks!

My reason for asking was to get a better idea of the amount of data forwarded by certain classes of forwarders in our environment as to better set the MaxQueueSize in outputs.conf in the event of Indexer failure.

0 Karma

_d_
Splunk Employee
Splunk Employee

No problems. Please consider upvoting and accepting the answer so that other members can benefit from it. Thanks.

0 Karma

_d_
Splunk Employee
Splunk Employee

Yes, install Deployment Monitor app on Splunk Indexer and you will have access to really useful information/charts/dashboards about all your splunk instances including what you're looking for and more. If you are on Splunk 4.2.3 or later you just have to enable it (as it comes with it).
Otherwise use this link to get it: http://splunk-base.splunk.com/apps/22301/splunk-deployment-monitor

Hope this helps

> please upvote and accept answer if you find it useful - thanks!

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...