Getting Data In

Is there a REST API call or other method to check which files were processed by a Splunk forwarder in the past?

anoopambli
Communicator

I have a customer complaining that one of the sourcetype data is not appearing for couple of days in the past. I see the files for those dates are available in customer's server, but Splunk didn't pick them up for only few days. (10th - 14th) on all other days it worked. I don't find anything wrong with the Splunk config and couldn't find anything from the logs which says an issue about Splunk.

Question is, is there a REST call or any other method to find which files a Splunk forwarder processed in the past? Like if I wanted to check which files were processed by splunkforwarder yesterday; is there a way to find that?

0 Karma

Yasaswy
Contributor

Hi, something like
index=_internal host=yourForwarder earliest=-1d@d latest=@d per_source_thruput|stats avg(kb) by series
might help

0 Karma

maciep
Champion

I don't think this is what you're looking for exactly, but this should give you an idea of the files splunk is tailing.

index=_internal sourcetype=splunkd component="TailingProcessor" "adding watch"
0 Karma

anoopambli
Communicator

thanks for your reply. If i am not wrong splunkd will show those entries in log only after a recycle of forwarder.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...