Hi there,
I have 2 forwarders on a single box - one HF one UF. I want to switch off the UF. Im looking for a list of sourcetypes that the UF is sending. Does anyone have a search that can tell me what sourcetypes are actively sending data to Splunk via the UF's GUID ?
Thanks!
They both use the same - right now no option to change. I know i can use btool and list monitor to get a list of inputs.. but was hoping there was a way of generating a more "active" result from search.