Splunk Enterprise Security

events and forwarders

trojan_81
Path Finder

Hi

When i'm reviewing an EVent, is there a field that tells me if it came from a forwarder?

0 Karma

woodcock
Esteemed Legend

Most of the time the host field but occasionally this is borked and you have to get what you need from the source field.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Not specifically. Compare the host field to your list of forwarders.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

[Puzzles] Solve, Learn, Repeat: Nested loops in Event Conversion

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...