Getting Data In

Why do I see more hosts than actual configured forwarders under Data Summary on the Splunk server? Will data be collected from these unconfigured hosts?

etaga
New Member

I configured only 3 hosts as forwarders, but in App > Search & Reporting > Data Summary, I found more hosts and some of them are not configured as forwarders. Is possible that the Splunk server collects logs from hosts that are not configured as forwarders?

Thank you,
Egi

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi etaga,

in inputs.conf on your indexer you can use the acceptFrom = ... option to restrict or allow connection. See the docs for more details http://docs.splunk.com/Documentation/Splunk/6.2.4/admin/inputsconf

cheers, MuS

Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...