Getting Data In

Determine Universal Forwarder vs Other Forwarder from Logs

David
Splunk Employee
Splunk Employee

I know that you can run splunk version to get an output telling you whether a Splunk install has the UF binaries or the full binaries, but is there ever anything logged? I did a search of my $SPLUNK_HOME/var/log/splunk and didn't find the word "universal" anywhere.

Tags (1)
0 Karma
1 Solution

mcmaster
Communicator

Try this search:

index=_internal fwdtype sourcetype=splunkd component=Metrics | table host fwdType | dedup host

I've never run that search before today, but it appears based on our systems to log "uf" for Universal Forwarders and "full" for a Splunk Enterprise install.

Hope that helps.

View solution in original post

mcmaster
Communicator

Try this search:

index=_internal fwdtype sourcetype=splunkd component=Metrics | table host fwdType | dedup host

I've never run that search before today, but it appears based on our systems to log "uf" for Universal Forwarders and "full" for a Splunk Enterprise install.

Hope that helps.

Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...