Getting Data In

How can I find a listing of all universal forwarders that I have in my Splunk environment?

johannterc
New Member

Hello. How can I find a listing of all universal forwarders that I have in my Splunk environment?

0 Karma
1 Solution

masonmorales
Influencer

Here's what I would use:

index=_internal source=*metrics.log* group=tcpin_connections os=* uf  | eval os=os." ".arch | eval version=version." (".build.")" | stats latest(fwdType) AS forwarder_type latest(os) AS os latest(version) AS version by hostname | rename hostname as splunk_forwarder | replace uf with "Universal", full with "Full" in forwarder_type | rename splunk_forwarder as "Splunk Forwarder", forwarder_type as "Forwarder Type", os as "Operating System", version as Version

View solution in original post

jkat54
SplunkTrust
SplunkTrust

| metadata type=hosts | search NOT [ search index=_internal | fields splunk_server | dedup splunk_server | format ]

I feel like there is a field in '| metadata type=hosts' which specifies if it's a forwarder
Or not but the search above might work too.

0 Karma

ddrillic
Ultra Champion

How does your serverclass.conf look on the deployment server? My favorite place ; -)

0 Karma

masonmorales
Influencer

Here's what I would use:

index=_internal source=*metrics.log* group=tcpin_connections os=* uf  | eval os=os." ".arch | eval version=version." (".build.")" | stats latest(fwdType) AS forwarder_type latest(os) AS os latest(version) AS version by hostname | rename hostname as splunk_forwarder | replace uf with "Universal", full with "Full" in forwarder_type | rename splunk_forwarder as "Splunk Forwarder", forwarder_type as "Forwarder Type", os as "Operating System", version as Version

skoelpin
SplunkTrust
SplunkTrust

Try this

index=_internal source=*metrics.log group=tcpin_connections
| eval sourceHost=if(isnull(hostname), sourceHost,hostname)

0 Karma
Get Updates on the Splunk Community!

Advanced Splunk Data Management Strategies

Join us on Wednesday, May 14, 2025, at 11 AM PDT / 2 PM EDT for an exclusive Tech Talk that delves into ...

Uncovering Multi-Account Fraud with Splunk Banking Analytics

Last month, I met with a Senior Fraud Analyst at a nationally recognized bank to discuss their recent success ...

Secure Your Future: A Deep Dive into the Compliance and Security Enhancements for the ...

What has been announced?  In the blog, “Preparing your Splunk Environment for OpensSSL3,”we announced the ...