Getting Data In

Is there a way to find out all the indexers and forwarders in our Splunk environment via Splunk Web or CLI?

japala
Path Finder

It would be great if someone can help me get this answer, either in GUI or CLI (through commands). Thank you in advance.

martin_mueller
SplunkTrust
SplunkTrust

Assuming you're on a recent version of Splunk, hit Settings in the top right corner and open the Distributed Management Console, big green icon.

http://docs.splunk.com/Documentation/Splunk/6.3.0/DMC/DMCoverview

MuS
SplunkTrust
SplunkTrust

Hi japala,

DMC should be the best option, but it will only show your environment correct if all internal logs are forwarded to the indexers and the Splunk instance running DMC has all indexers as search peer, see the docs for more detail http://docs.splunk.com/Documentation/Splunk/6.3.0/DMC/DMCoverview

cheers, MuS

0 Karma

Yasaswy
Contributor

Hi.. yes... Best would be to use the S.o.S Splunk app. It should provide what you need and more. You can also search internal index(depending on your environment/search head configuration). Eg: Something like
index=_internal earliest=-30m per_index_thruput will give you info on the data received from various hosts in the past 30 min from indexers responding to your search head... check out the available Fields and tweak the search per your requirement. You do this on Web or Use CLI /REST.

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...