This app should give you all of the hosts that are connecting/sending data:
http://splunk-base.splunk.com/apps/22301/splunk-deployment-monitor
Deployment Monitor also has searches to alert you when a host stops sending data or if a host starts sending more/less than usual.
A search similiar to this should also work:
* earliest=-24h| dedup host | stats count
this command is not working on splunk forwader cli, do you know any other or i'm doing wrong
Hmm, now that I think about it this won't quite work for the explanation with the forwarder between.
How about a query or an update to this App nolonger on splunkbase
Exactly. Also were using Splunk 4.1.7 (95063).
so: UF or LF --> Forwarder --> indexer?
Hosts are sending logs to the forwarder via lightweight forwarder.
How are the other hosts sending the data to the forwarder?