Getting Data In

Why do I see more hosts than actual configured forwarders under Data Summary on the Splunk server? Will data be collected from these unconfigured hosts?

etaga
New Member

I configured only 3 hosts as forwarders, but in App > Search & Reporting > Data Summary, I found more hosts and some of them are not configured as forwarders. Is possible that the Splunk server collects logs from hosts that are not configured as forwarders?

Thank you,
Egi

0 Karma

MuS
Legend

Hi etaga,

in inputs.conf on your indexer you can use the acceptFrom = ... option to restrict or allow connection. See the docs for more details http://docs.splunk.com/Documentation/Splunk/6.2.4/admin/inputsconf

cheers, MuS

Get Updates on the Splunk Community!

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Thanks for the Memories! Splunk University, .conf24, and Community Connections

Thank you to everyone in the Splunk Community who joined us for .conf24 – starting with Splunk University and ...

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...