Hi,
I have configured a couple of new hosts to forward Windows logs directly to Splunk cloud rather than going via on prem Splunk. I have implemented this configured on a Splunk distribution server and defined the hosts via server class.
I can see the hosts logs appearing in Splunk but am unsure how to verify they are being injested via Splunk cloud rather than on prem.
Could someone advise on how I can validate this?
Thanks
Check the forwarder's splunkd.log to see which indexer(s) it's connecting to.