I just upgrade to Splunk 4.3.2 from Splunk 4.2.3 and I noticed that the follow events are no longer being populated in the internal index:
ForwarderInfo build=119532 version=4.3.1 os=Windows arch=Intel hostname=server.example.com guid=97A6EA09-9999-4F09-B659-4DDB03C4D729 fwdType=uf ssl=false lastIndexer=172.16.1.149:9997
Any ideas on how/why this information went away?
they are still in the internal in the metrics.log :
index="_internal" source="*metrics.log" os=* arch=* build=* hostname=*