Need help with splunk SPL or rest api to fetch areport where we can see the count of total servers(splunk universal forwarders) reporting to IDX and HF with breakup.
Some UF are sending data to IDXers directly and few of them are sending it via HF(due to some connection issues we have followed this architecture)
Please assist me on the same.
Hi @AK_Splunk
can you run query1 or query2 search in search head , hope one of helps your requriment
Query1
index=_internal source="*metrics.log" group="tcpin_connections"
| dedup hostname
| rename host as "receiver host" hostname as "sender host"
| table _time "sender host" connectionType version sourceIp destPort ssl fwdType "receiver host"
Query2
index=_internal source="*metrics.log" host IN (UF1,UF2)
group=tcpout_connections
| stats count by host destIp destPort