Getting Data In

How to get Splunk UF versions in Intermediate forwarder set up?

dmcintosh1972
Explorer

Hi can anyone think of a way to get Splunk versions reported from universal forwarders when in a Intermediate forwarder environment.

I have tried searches like 

index=_internal sourcetype=splunkd group=tcpin_connections
but it only returns the agent version of the intermediate layer, not the UF versions behind it.

Are there any commands that can be deployed via to each UF to collect that information?

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The intermediate forwarders should be logging the tcpin_connection events they get from UFs (at least if they're heavy forwarders).  Check that they are forwarding their logs

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

dmcintosh1972
Explorer

Hi

FYI

limits.conf
[metrics:tcpin_connections]
aggregate_metrics = true

this setting will aggregate the data being received on the Intermediate forwarders so does not report the individual servers.

0 Karma

dmcintosh1972
Explorer

thanks for your help, not sure if i need to enable something. to log more metrics?
from UF i only see the group fields per_host_thruput, instance.

The group=tcpin_connections are only logged under my cloud indexers and the hostnames covered are the cloud infrastructure and the IUF's, now other UF servers.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The intermediate forwarders should be logging the tcpin_connection events they get from UFs (at least if they're heavy forwarders).  Check that they are forwarding their logs

---
If this reply helps you, Karma would be appreciated.
0 Karma

isoutamo
SplunkTrust
SplunkTrust

UFs are reporting their version just like IUFs, just check/add their name to your query.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...