Getting Data In

How to list inactive forwarders in Splunk search

jamin358
Explorer

Im tring to come up with a way of listing all my forwarders (on or off) in a list and display whether they are active or inactive.

There is no guarentee that they will be turned on after a certain amount of time. I would prefer a solution where I don't have to search through all time just to get all the host names in a list.

I know that if I were to run the search over all time, I would do something with:
index=* host=* | dedup host
and then look for the last log instance and see if its discussing the shutdown procedure and status. - But this is very costly.

Surely Splunk has something built in that remembers what forwarders have connected in the past or something?

I have UF's on both windows and Linux machines.

Thanks in advance

0 Karma

adonio
Ultra Champion

hello there,

hope i understand your question / requirement.
try the | metadata command
elaborated article and examples here:
https://docs.splunk.com/Documentation/SplunkCloud/7.0.0/SearchReference/Metadata

hope it helps

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...