Getting Data In

Monitoring universal forwarder events

New Member


I have installed splunk on a FreeBSD 8.3 server and a universal forwarder on a different FreeBSD machine that I need to send logs and system health. The forwarder has been configured to communicate with the server and I can see the connections in the deployment monitor.
My question is how do I monitor what information is being send and where can I find this information on the main server. Do I have to perform some further configuration to the universal forwarder? Any help will be appreciated!


0 Karma

New Member

Ok I got the part of sending events via cli

But I still can't find any information on how to forward CPU and Memory stats 😞

0 Karma
Get Updates on the Splunk Community!

Splunk Cloud | Empowering Splunk Administrators with Admin Config Service (ACS)

Greetings, Splunk Cloud Admins and Splunk enthusiasts! The Admin Configuration Service (ACS) team is excited ...

Tech Talk | One Log to Rule Them All

One log to rule them all: how you can centralize your troubleshooting with Splunk logs We know how important ...

Splunk Security Content for Threat Detection & Response, Q1 Roundup

Join Principal Threat Researcher, Michael Haag, as he walks through: An introduction to the Splunk Threat ...