I currently use the monitoring console to tell me if a Forwarder has not reported in the last 15 min & I consider that FW gone plus I check the list of decommissioned Hosts to consider a FW + Host gone for good! Well, what if the FW software has an issue & the host is just fine? Is there a SPL or way to tell if the Forwarder agent / SW is broken, so I can at least troubleshoot or re-install the FW? Thank u for your help in advance.
Or it could be a network problem and both the host and UF are fine. How would you determine that? Unfortunately, as good as Splunk is it can't answer all questions or solve all problems. Sometimes you have to revert to old-fashioned IT grunt work - log in to the box, call someone who can log in to the box, ask the network team if there's a problem, etc.
Or it could be a network problem and both the host and UF are fine. How would you determine that? Unfortunately, as good as Splunk is it can't answer all questions or solve all problems. Sometimes you have to revert to old-fashioned IT grunt work - log in to the box, call someone who can log in to the box, ask the network team if there's a problem, etc.