Getting Data In

Where did the ForwarderInfo events go after upgrading to Splunk 4.3?

Lowell
Super Champion

I just upgrade to Splunk 4.3.2 from Splunk 4.2.3 and I noticed that the follow events are no longer being populated in the internal index:

ForwarderInfo build=119532 version=4.3.1 os=Windows arch=Intel hostname=server.example.com guid=97A6EA09-9999-4F09-B659-4DDB03C4D729 fwdType=uf ssl=false lastIndexer=172.16.1.149:9997

Any ideas on how/why this information went away?

0 Karma

MarioM
Motivator

they are still in the internal in the metrics.log :

index="_internal" source="*metrics.log" os=* arch=* build=* hostname=*
0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...