Getting Data In

How to determine if forwarder is phoning home to deployment server

dolfantimmy
Path Finder

What is the easiest way to determine if a specific forwarder is phoning home to the deployment server?

anakor
Engager

How to check the list of Universal Forwarders in the CLI of the Deployment Server? (Splunk versions 6/7)

0 Karma

lguinn2
Legend

I like @chanfoli's answer, but you can also do this:

Splunk 6: Is the deployment client phoning home?

index=_internal (*phonehome* component=DC*) OR (component=DC:HandshakeReplyHandler) host=hostname
| sort _time
| table _time host log_level message

In Splunk 5, the Splunk internal log format was a bit different. You could also use a similar search to identify clients that were phoning home yesterday, but have not phoned home today:

index=_internal (*phonehome* component=DC*) OR (component=DC:HandshakeReplyHandler) earliest=-2d
| eval Day=if(_time>(now()-86400),"Today","Yesterday")
| chart count by host day
| where Yesterday>0 AND Today<0

chanfoli
Builder

Via splunk web on the deployment server. Go to settings->forwarder management, select the clients and type in part of the hostname in the filter text box. If it is phoning home it should show up there with app count and time since last phone-home.

dolfantimmy
Path Finder

Thank you for your response. However, when on the web ui on the deployment server, I see no "settings->forwarder management"

0 Karma

dolfantimmy
Path Finder

I should note, this is version 5.0.1

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...