Monitoring Splunk

How do I find a missing forwarder Monitoring console reports & fixing the issue?

SamHTexas
Builder

How do I find a missing forwarder Monitoring console reports & fixing the issue? I select the item in monitoring console for the missing forwarder but does not indicate what or where? Then if found what are the steps to fix or replace the forwarder. Thank u

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The MC knows about forwarders as concepts, but doesn't know where they are physically (what data center) or virtually (which servers they run on).  That information should be in your CMDB.

If a forwarder is reported as missing then the steps to take are:

  1. Find the forwarder
  2. Verify the server is up
  3. Verify the forwarder is running
  4. Verify network connectivity between the forwarder and the indexers
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...