Getting Data In

How to list inactive forwarders in Splunk search

jamin358
Explorer

Im tring to come up with a way of listing all my forwarders (on or off) in a list and display whether they are active or inactive.

There is no guarentee that they will be turned on after a certain amount of time. I would prefer a solution where I don't have to search through all time just to get all the host names in a list.

I know that if I were to run the search over all time, I would do something with:
index=* host=* | dedup host
and then look for the last log instance and see if its discussing the shutdown procedure and status. - But this is very costly.

Surely Splunk has something built in that remembers what forwarders have connected in the past or something?

I have UF's on both windows and Linux machines.

Thanks in advance

0 Karma

adonio
Ultra Champion

hello there,

hope i understand your question / requirement.
try the | metadata command
elaborated article and examples here:
https://docs.splunk.com/Documentation/SplunkCloud/7.0.0/SearchReference/Metadata

hope it helps

0 Karma
Get Updates on the Splunk Community!

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Index This | What goes away as soon as you talk about it?

May 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

What's New in Splunk Observability Cloud and Splunk AppDynamics - May 2025

This month, we’re delivering several new innovations in Splunk Observability Cloud and Splunk AppDynamics ...