Is there any specific search that i can pull out the connection established time and date?
Tcp_connection group event will be written to _internal index, when a UF connects to an indexer.
List of Forwarders that have connected in the last 3 minutes:
index=_internal group="tcpin_connections" startminutesago=3 | stats count(sourceHost) by sourceHost
Tcp_connection group event will be written to _internal index, when a UF connects to an indexer.
List of Forwarders that have connected in the last 3 minutes:
index=_internal group="tcpin_connections" startminutesago=3 | stats count(sourceHost) by sourceHost