Security

Validating the path logs are taking to get to Splunk

cbrissett
Engager

Hi,

I have configured a couple of new hosts to forward Windows logs directly to Splunk cloud rather than going via on prem Splunk. I have implemented this configured on a Splunk distribution server and defined the hosts via server class.

I can see the hosts logs appearing in Splunk but am unsure how to verify they are being injested via Splunk cloud rather than on prem.

Could someone advise on how I can validate this?

Thanks

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Check the forwarder's splunkd.log to see which indexer(s) it's connecting to.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...

Auto-Injector for Everything Else: Making OpenTelemetry Truly Universal

You might have seen Splunk’s recent announcement about donating the OpenTelemetry Injector to the ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...