Getting Data In

Search to find when a forwarder restarted?

a212830
Champion

Hi,

Is there a search that I can run that shows when a forwarder starts, and is considered up and running? I want to create transactions - one that shows it starts and is running, and another that shows it started but isn't running (and therefore some errors may exist).

0 Karma

thomrs
Communicator

There are messages in the internal logs, _*.

index =_*  host=<fwd name> starting

Even better is the deployment app, look for all kinds of things and is easy to setup alerts.

https://apps.splunk.com/app/1294/

0 Karma
Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...