Getting Data In

How to get a list of all hosts installed with Universal Forwarder

Vetrikmr
New Member

I have a bunch of agents(hosts) in Appdynamics, I wanted to figure out that the Universal Forwarder is installed or not in all those hosts to collect logs to Splunk.
Is there any way that I can get the list of hosts that installed with UF.

Thanks in advance.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi Vetrikmr
if you want to find servers that sent logs to Indexers you can use the Monitor Console, in this way you have many additional information about them.
If instead you want to know Universal Forwarderd connected to a deployment Server you have to access it and go in [Settings -- Forwarders Management].

Bye.
Giuseppe

0 Karma

harsmarvania57
Ultra Champion

Hi,

You can run below query to find out which hosts are sending data to your splunk instance.

index="_internal" source="*metrics.log*" group=tcpin_connections | dedup hostname| table hostname,sourceIp,fwdType,guid,version,build,os,arch

If you want to find only universal forwarders then please use below query.

index="_internal" source="*metrics.lo*" group=tcpin_connections  fwdType=uf | dedup hostname| table hostname,sourceIp,fwdType,guid,version,build,os,arch

ninjaneer68
New Member

For your two queries, what would be a good way to get lastseen added to it ?

Trying to get a list of all forwarders and when splunk last saw the UF report back into splunk

Tags (1)
0 Karma

kairobin
Path Finder

Hello
This really sums it all up to me. 

index="_internal" source="*metrics.lo*" group=tcpin_connections fwdType=uf
| stats latest(_time) as lastSeen by hostname, sourceIp, fwdType, guid, version, build, os, arch
| eval lastSeenFormatted = strftime(lastSeen, "%Y-%m-%d %H:%M:%S")
| eval timeDifferenceSec = now() - lastSeen
| eval timeSinceLastSeen = tostring(floor(timeDifferenceSec / 3600)) . "h " . tostring(round((timeDifferenceSec % 3600) / 60)) . "m"
| table hostname, sourceIp, fwdType, guid, version, build, os, arch, lastSeenFormatted, timeSinceLastSeen
0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...