Getting Data In

Internal field for originating forwarder

mikaelbje
Motivator

Is there a way to see the originating forwarder for a specfic event? I haven't found any internal/metadata fields. There are scenarios where it would be interesting to pinpoint the exact intermediate forwarder. Something like "splunk_server" but for forwarders.

Tags (2)
0 Karma
1 Solution

mikaelbje
Motivator

I finally found a way to achieve this in another thread: http://answers.splunk.com/answers/1453/how-do-i-add-metadata-to-events-coming-from-a-splunk-forwarde...

You need to manually add the metadata field, but it should suffice.

View solution in original post

0 Karma

mikaelbje
Motivator

I finally found a way to achieve this in another thread: http://answers.splunk.com/answers/1453/how-do-i-add-metadata-to-events-coming-from-a-splunk-forwarde...

You need to manually add the metadata field, but it should suffice.

0 Karma

mikaelbje
Motivator

No official comment here? This is very useful especially if one has a chain of forwarders and want to see where the event came in, which forwarder passed it on etc.

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...