Monitoring Splunk

How do I deal with missing short list of Forwarders reported by MC daily ? Thank u in advance.

SamHTexas
Builder

I get an ongoing short list of "Missing Forwarders" reported by Monitoring console. When you click on a missing FW. It shows it's IP, OS, Received counts, connection count , Avg KB/s and so on. So why are they reporting as missing then? How do attend to the missing? Can I ever get this down to 5 -10 number?

Labels (1)
Tags (1)
0 Karma

gcusello
Esteemed Legend

Hi @SamHTexas,

a missing Forwarder on MC is a Forwarder that sent logs (and data) in tha past but is isn't sending logs from, al least, last15 minutes.

For this reason you have all the information about it,even if it's missing.

Ciao.

Giuseppe

0 Karma

SamHTexas
Builder

Gracia, So how do I find if the FW is really broken or not? Also please tell me how to find out how often is the FW is set to send data. Thank u again.

Tags (1)
0 Karma

gcusello
Esteemed Legend

Hi @SamHTexas,

As I said, if a Forwarder is flagged as "missing" you can be sure that the Forwarder isn't sending logs from 15 minutes, this means that you can filter on the MC the Forwarders by Status to display only the missing one and you'll have a short (hopefully!) list of missing Forwarders.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Splunk Security Content for Threat Detection & Response, Q1 Roundup

Join Principal Threat Researcher, Michael Haag, as he walks through:An introduction to the Splunk Threat ...

Splunk Life | Happy Pride Month!

Happy Pride Month, Splunk Community! 🌈 In the United States, as well as many countries around the ...

SplunkTrust | Where Are They Now - Michael Uschmann

The Background Five years ago, Splunk published several videos showcasing members of the SplunkTrust to share ...