Getting Data In

How to list inactive forwarders in Splunk search

jamin358
Explorer

Im tring to come up with a way of listing all my forwarders (on or off) in a list and display whether they are active or inactive.

There is no guarentee that they will be turned on after a certain amount of time. I would prefer a solution where I don't have to search through all time just to get all the host names in a list.

I know that if I were to run the search over all time, I would do something with:
index=* host=* | dedup host
and then look for the last log instance and see if its discussing the shutdown procedure and status. - But this is very costly.

Surely Splunk has something built in that remembers what forwarders have connected in the past or something?

I have UF's on both windows and Linux machines.

Thanks in advance

0 Karma

adonio
Ultra Champion

hello there,

hope i understand your question / requirement.
try the | metadata command
elaborated article and examples here:
https://docs.splunk.com/Documentation/SplunkCloud/7.0.0/SearchReference/Metadata

hope it helps

0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...