Getting Data In

How to verify if Splunk Forwarder is receiving the data on a UDP port

ssankeneni
Communicator

How can I verify if my universal forwarder is receiving the data on the UDP port ? I don't see any thing in my splunkd logs.

0 Karma

Ayn
Legend

Easiest is to run something like tcpdump, Wireshark or similar and see if traffic flows in on the port.

0 Karma

Ayn
Legend

index=_internal group=per_source_thruput series=udp:514

ssankeneni
Communicator

I don't have access to the machine to install any new rpms. Can you please let me know is there any way i could find it through Splunk.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...