Monitoring Splunk

How do I deal with missing short list of Forwarders reported by MC daily ? Thank u in advance.

SamHTexas
Builder

I get an ongoing short list of "Missing Forwarders" reported by Monitoring console. When you click on a missing FW. It shows it's IP, OS, Received counts, connection count , Avg KB/s and so on. So why are they reporting as missing then? How do attend to the missing? Can I ever get this down to 5 -10 number?

Labels (1)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @SamHTexas,

a missing Forwarder on MC is a Forwarder that sent logs (and data) in tha past but is isn't sending logs from, al least, last15 minutes.

For this reason you have all the information about it,even if it's missing.

Ciao.

Giuseppe

0 Karma

SamHTexas
Builder

Gracia, So how do I find if the FW is really broken or not? Also please tell me how to find out how often is the FW is set to send data. Thank u again.

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @SamHTexas,

As I said, if a Forwarder is flagged as "missing" you can be sure that the Forwarder isn't sending logs from 15 minutes, this means that you can filter on the MC the Forwarders by Status to display only the missing one and you'll have a short (hopefully!) list of missing Forwarders.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...