Getting Data In

How to check how many hosts are connecting (sending logs) to Splunk Forwarder

Explorer

Hi Guys,

We have a remote site with a Splunk forwarder installed. How to check how many hosts are connecting (sending logs) to that Splunk Forwarder?

Thanks,

0 Karma

Motivator

This app should give you all of the hosts that are connecting/sending data:
http://splunk-base.splunk.com/apps/22301/splunk-deployment-monitor

Deployment Monitor also has searches to alert you when a host stops sending data or if a host starts sending more/less than usual.

A search similiar to this should also work:

* earliest=-24h| dedup host | stats count

0 Karma

New Member

this command is not working on splunk forwader cli, do you know any other or i'm doing wrong

0 Karma

Motivator

Hmm, now that I think about it this won't quite work for the explanation with the forwarder between.

0 Karma

New Member

How about a query or an update to this App nolonger on splunkbase

0 Karma

Explorer

Exactly. Also were using Splunk 4.1.7 (95063).

0 Karma

Motivator

so: UF or LF --> Forwarder --> indexer?

0 Karma

Explorer

Hosts are sending logs to the forwarder via lightweight forwarder.

0 Karma

Motivator

How are the other hosts sending the data to the forwarder?

0 Karma