Getting Data In

How can we identify forwarders which are not connected to certain indexers?

ddrillic
Ultra Champion

The DMC shows us the following -

alt text

It shows the connected forwarders to the four indexers, the yellow line is actually two indexers one on top of the other.

How can we figure out which two hundred or so forwarders are not connected to the two newer indexers (the blue and purple) at the bottom of the chart?

Tags (2)
0 Karma

ddrillic
Ultra Champion

Jeff suggested -

-- You should be able to run a search on _internal for the last 24 hours looking for host whose count of splunk_server != 4.

0 Karma

rharrisssi
Path Finder

I know this isn't what you're asking, but having hundreds of forwarders going directly to your indexers is against best practice. The Heavy Forwarder role should be intercepting these messages from the UFs and such and then forwarding them to the indexers.

This also allows you to do some preprocessing with transforms and props that would otherwise take resources away from your indexers.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...