Getting Data In

How far back can be go when rebuilding the forwarders' assets?

ddrillic
Ultra Champion

Based on the interface of the DMC, it appears that we can go back only 24 hours when rebuilding the forwarder assets. I just did it in our production environment and only one forwarder is reported as missing. I'm pretty sure though that other forwarders are down for more than 24 hours. What can be done?

alt text

Tags (2)
0 Karma

Claw
Splunk Employee
Splunk Employee

Are you trying to collect the data from the missing forwarders or are you trying to add the forwarders to the Distributed Management Console.

This process deletes the sourcetype holding all of the existing forwarders and the process is usesually ONLY run oneself or so to clean up an environment where you have many forwarders missing and only want to see existing forwarders. Once you run this process, any forwarders that are no longer reporting are just gone and so is any data about them. This is not retrievable. The 24 hour question is asking how much back data for each forwarder do you want to collect. It cannot collect any data from forwarders that it no longer has any record of.

0 Karma

ddrillic
Ultra Champion

So, let's say a certain forwarder was down for 48 hours. Would it be included in the rebuilt list?

0 Karma

ddrillic
Ultra Champion

@Claw - any feedback on this one, by any chance?

0 Karma

ddrillic
Ultra Champion

Any thoughts about this one, by any chance?

0 Karma
Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

Industry Solutions for Supply Chain and OT, Amazon Use Cases, Plus More New Articles ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...