Getting Data In

Why is the Universal Forwarder indexing its own logs?

wvalente
Explorer

Guys.

I have many Universal Forwarders installed in the machines that send logs to one Heavy Forwarder.

This Heavy Forwarder sends log to my indexer.

I do not know why each universal forwarder is sending its own internal logs (splunkd, metrics, etc) and indexing this data. I do not want the internal logs from each universal forwarder.

I've tried to filter these logs in the heavy forwarder, but it's not working.

What can I do?

Thanks.

0 Karma

bcyates
Communicator

It is best practice to index _internal logs. Your Distributed Monitoring Console won't fully work without it and you won't really be able to remotely troubleshoot any problems on your UFs.

If you are worried about the amount of data in the index, just adjust frozenTimePeriodinSecs on those indexes so you don't hang on to them for too long

0 Karma

FrankVl
Ultra Champion

You can disable those inputs on the Universal Forwarder.

But usually these internal logs are considered very useful for monitoring the health of those instances and troubleshooting issues with data feeds, so I would highly recommend keeping them enabled actually.

Also: since this is going into _internal index, this is not counting against your license (if that is what you were worried about).

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...