Monitoring Splunk

Trouble-shooting events forwarded from a heavy forwarder.

willsy
Communicator

Hello, 

Are there searches or any log files that will tell me what is being forwarded from my heavy forwarder? 

I have a multi site, clustered splunk environment that ingests all its own personal logs first but then sends all of the data to a third party via a heavy forwarder and data diode. I do not have access to the data once they have been sent from the HF so i cannot assess what has been sent. 

Are there any splunk techniques, searches, log files i can view from my heavy forwarder to determine what data have been sent to the data diode? 

I can provide config files if required. 

Labels (2)
Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

One thing what you could try is adding that HF as indexer on you MC. Then it could shows some information what it has done e.g. what logs it has managed? This is nice way to see e.g. HEC statistic on HF. There is already item for thi (add HF as own type to MC or something similar) on https://ideas.splunk.com

r. Ismo

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @willsy  try this search.. 

index=_internal sourcetype=splunkd group=per_host_thruput host=<HF-Name>

or, 

index=_internal sourcetype=splunkd group=per_host_thruput 

then you can click host field on left side field selector, and select the HF manually. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

willsy
Communicator

Hi @inventsekar what does that search specifically tell me? 

i am hoping that it is the hosts that are being forwarded by the HF if that is the case then bosh, my stuff works as it is meant to and your search gets the karma.


0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...