Getting Data In

How to list inactive forwarders in Splunk search

jamin358
Explorer

Im tring to come up with a way of listing all my forwarders (on or off) in a list and display whether they are active or inactive.

There is no guarentee that they will be turned on after a certain amount of time. I would prefer a solution where I don't have to search through all time just to get all the host names in a list.

I know that if I were to run the search over all time, I would do something with:
index=* host=* | dedup host
and then look for the last log instance and see if its discussing the shutdown procedure and status. - But this is very costly.

Surely Splunk has something built in that remembers what forwarders have connected in the past or something?

I have UF's on both windows and Linux machines.

Thanks in advance

0 Karma

adonio
Ultra Champion

hello there,

hope i understand your question / requirement.
try the | metadata command
elaborated article and examples here:
https://docs.splunk.com/Documentation/SplunkCloud/7.0.0/SearchReference/Metadata

hope it helps

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...