Monitoring Splunk

How do I deal with missing short list of Forwarders reported by MC daily ? Thank u in advance.

SamHTexas
Builder

I get an ongoing short list of "Missing Forwarders" reported by Monitoring console. When you click on a missing FW. It shows it's IP, OS, Received counts, connection count , Avg KB/s and so on. So why are they reporting as missing then? How do attend to the missing? Can I ever get this down to 5 -10 number?

Labels (1)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @SamHTexas,

a missing Forwarder on MC is a Forwarder that sent logs (and data) in tha past but is isn't sending logs from, al least, last15 minutes.

For this reason you have all the information about it,even if it's missing.

Ciao.

Giuseppe

0 Karma

SamHTexas
Builder

Gracia, So how do I find if the FW is really broken or not? Also please tell me how to find out how often is the FW is set to send data. Thank u again.

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @SamHTexas,

As I said, if a Forwarder is flagged as "missing" you can be sure that the Forwarder isn't sending logs from 15 minutes, this means that you can filter on the MC the Forwarders by Status to display only the missing one and you'll have a short (hopefully!) list of missing Forwarders.

Ciao.

Giuseppe

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...