Getting Data In

splunk forwarder showing different events indexed than splunk indexer

remy06
Contributor

Hi,

Just to check, I've a splunk forwarder that shows lesser events indexed than on the splunk indexer.Is it suppose to be like this?

For eg, on a windows server I've this forwarder installed and configured to send winevent logs to splunk indexer. The forwarder itself shows 26,434 events indexed while on the splunk indexer shows 253,118.

I've configured forwarding defaults NOT to store a local copy of forwarded events so has it got anything to do with this?

Tags (2)
0 Karma
1 Solution

e82than
Communicator

hi remy06,

By not getting your fowarder to keep a copy of the data, the results differ.

"I've configured forwarding defaults NOT to store a local copy of forwarded events so has it got anything to do with this?"

R, Ethan Hunt.

View solution in original post

e82than
Communicator

hi remy06,

By not getting your fowarder to keep a copy of the data, the results differ.

"I've configured forwarding defaults NOT to store a local copy of forwarded events so has it got anything to do with this?"

R, Ethan Hunt.

Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...