Getting Data In
Highlighted

Why do I see more hosts than actual configured forwarders under Data Summary on the Splunk server? Will data be collected from these unconfigured hosts?

New Member

I configured only 3 hosts as forwarders, but in App > Search & Reporting > Data Summary, I found more hosts and some of them are not configured as forwarders. Is possible that the Splunk server collects logs from hosts that are not configured as forwarders?

Thank you,
Egi

0 Karma
Highlighted

Re: Why do I see more hosts than actual configured forwarders under Data Summary on the Splunk server? Will data be collected from these unconfigured hosts?

SplunkTrust
SplunkTrust

Hi etaga,

in inputs.conf on your indexer you can use the acceptFrom = ... option to restrict or allow connection. See the docs for more details http://docs.splunk.com/Documentation/Splunk/6.2.4/admin/inputsconf

cheers, MuS