Monitoring Splunk

How do I deal with missing short list of Forwarders reported by MC daily ? Thank u in advance.

SamHTexas
Builder

I get an ongoing short list of "Missing Forwarders" reported by Monitoring console. When you click on a missing FW. It shows it's IP, OS, Received counts, connection count , Avg KB/s and so on. So why are they reporting as missing then? How do attend to the missing? Can I ever get this down to 5 -10 number?

Labels (1)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @SamHTexas,

a missing Forwarder on MC is a Forwarder that sent logs (and data) in tha past but is isn't sending logs from, al least, last15 minutes.

For this reason you have all the information about it,even if it's missing.

Ciao.

Giuseppe

0 Karma

SamHTexas
Builder

Gracia, So how do I find if the FW is really broken or not? Also please tell me how to find out how often is the FW is set to send data. Thank u again.

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @SamHTexas,

As I said, if a Forwarder is flagged as "missing" you can be sure that the Forwarder isn't sending logs from 15 minutes, this means that you can filter on the MC the Forwarders by Status to display only the missing one and you'll have a short (hopefully!) list of missing Forwarders.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...