Hi. My environment is running splunk stream app.
Logs from my windows environment servers are streamed to a heavy forwarder and then out to splunk cloud.
The index it falls under is: index=stream
I am trying to determine if a particular windows server stream data is making it. The streamfwd process on the server is running. The server is named: server1
At the indexer, I tried running a search of this but nothing returns: index=stream host=server1
If I run a search like this, I see one HOST and 100+ hostnames in the same event: index=stream hostname{}=server1
Any recommendation?