Monitoring Splunk

How do I deal with missing short list of Forwarders reported by MC daily ? Thank u in advance.

SamHTexas
Builder

I get an ongoing short list of "Missing Forwarders" reported by Monitoring console. When you click on a missing FW. It shows it's IP, OS, Received counts, connection count , Avg KB/s and so on. So why are they reporting as missing then? How do attend to the missing? Can I ever get this down to 5 -10 number?

Labels (1)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @SamHTexas,

a missing Forwarder on MC is a Forwarder that sent logs (and data) in tha past but is isn't sending logs from, al least, last15 minutes.

For this reason you have all the information about it,even if it's missing.

Ciao.

Giuseppe

0 Karma

SamHTexas
Builder

Gracia, So how do I find if the FW is really broken or not? Also please tell me how to find out how often is the FW is set to send data. Thank u again.

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @SamHTexas,

As I said, if a Forwarder is flagged as "missing" you can be sure that the Forwarder isn't sending logs from 15 minutes, this means that you can filter on the MC the Forwarders by Status to display only the missing one and you'll have a short (hopefully!) list of missing Forwarders.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...