Splunk Enterprise

How to ensure we are receiving data from all UF?

izzie123
Path Finder

Hi

How can we find out the list of universal forwarders sending data to Splunk?

Also, how do we ensure that all the UF that have been configured are sending data to Splunk?

Thank you so much in advance

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The Monitoring Console will have a list of UFs if you've enabled forwarder monitoring.  You also can get a list of UFs from the Deployment Server.

The TrackMe app (https://splunkbase.splunk.com/app/4621) can help you see which UFs are not sending data.

---
If this reply helps you, Karma would be appreciated.

izzie123
Path Finder

Thank you for your answer, it helped.

Is there any way we can do it inline using a script?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Do *what* exactly using a script?  What do you mean by "script"?  

You can click on the magnifying glass icon in the MC's Forwarder dashboard panels to see the SPL that is used to populate that panel.  Then you can copy that SPL to use in your own query.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

Cisco Use Cases, ITSI Best Practices, and More New Articles from Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...