Getting Data In

Why do I see more hosts than actual configured forwarders under Data Summary on the Splunk server? Will data be collected from these unconfigured hosts?

etaga
New Member

I configured only 3 hosts as forwarders, but in App > Search & Reporting > Data Summary, I found more hosts and some of them are not configured as forwarders. Is possible that the Splunk server collects logs from hosts that are not configured as forwarders?

Thank you,
Egi

0 Karma

MuS
Legend

Hi etaga,

in inputs.conf on your indexer you can use the acceptFrom = ... option to restrict or allow connection. See the docs for more details http://docs.splunk.com/Documentation/Splunk/6.2.4/admin/inputsconf

cheers, MuS

Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...