Getting Data In

Regarding my Universal forwarder down intimation

zahab20
Engager

Dear Team,

This is to inform you that i have around 50 universal forwarder installed in my splunk environment.

How we can be aware that one of Universal forwarder has stopped sending the data to indexer?

 

Please help.

 

Regards,

Zahab Zia

Labels (1)

zahab20
Engager

Can you please mention the path ?

0 Karma

inventsekar
SplunkTrust
SplunkTrust

MC_8.0.0.png

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The Monitoring Console has a built-in alert for missing forwarders.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...