Getting Data In

How can I find out how often the forwarders are sending their logs to indexers?

rodneymitch80
Explorer

How can I find out how often the forwarders are sending their logs to indexers? How to search in splunk enterprise

 

Thanks,

RPM

Labels (1)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @rodneymitch80,

the first check to perform is surely the one hinted by @richgalloway ,

then you could run a search to understand the delay between timestamp and indextime:

index=*
| eval delta=_indextime-_time
| stats max(delta) AS max min(delta) AS min avg(delta) AS avg BY host

or

index=*
| bin span=1h _indextime
| eval delta=_indextime-_time, indextime=strftime(_indextime,"%Y-%m-%d %H:%M:%S")
| stats max(delta) AS max min(delta) AS min avg(delta) AS avg BY host indextime

Ciao.

Giuseppe

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Check inputs.conf. 

If the stanza name begins with monitor:// or WinEventLog:// then the log is forwarded whenever new data is detected (almost immediately).  The UF's own logs are processed by a monitor stanza.

if the stanza name begins with script:// then data will be forwarded according to the interval= setting (default is 60 seconds).

There are other stanza types, but these are most common for forwarding logs.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...