Monitoring Splunk

How do i validate Heavy Forwarder is forwarding logs to Indexer- On Heavy Forwarder

MayurMangoli
Loves-to-Learn Everything

I have a heavy forwarder, where all security devices logs have been pointed to HF, and from HF logs have been forwarded to Indexer, but as we don't have access for Indexer & Search Head.


I want to validate, that configuration done on HF for forwarded the particular types logs has is getting in the Indexer, How do i can verify that all logs are forwarding to indexer.

As can be observed in splunkd.log "TcpOutEloop" it shows the HF is connected to Indexer, where we can validate related to configuration for indexer.

is there any way to validate? My security device logs which are pointed to HF, are forwarding to Indexer.

Labels (1)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @MayurMangoli ,

the only way to check if a log was forwarded to an Indexers is, as @richgalloway said. to run a search on the Search head.

You don't have the information of which HF data passed through, but you can see if the original host sent data.

If you think that's interesting to know the hostname of the HF, you could upvote my request in Splunk Ideas, that's "Under Consideration" from Splunk: ideas.splunk.com/EID-l-1731

Ciao.

Giuseppe

0 Karma

isoutamo
SplunkTrust
SplunkTrust
@gcusello have you try to add _meta tag in your HF/UF's inputs.conf and put that information there? I think that this could solve your needs?
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @isoutamo ,

yes I usually do it 😉

Ciao.

Giuseppe

richgalloway
SplunkTrust
SplunkTrust

You need access to the search head to confirm the data has been received properly.  Coordinate that with your Splunk admin(s)

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...