Splunk Enterprise

find out which Splunk server received the event.

rabrahaham
Engager

I all as an architect sometimes I find myself in environment where the inputs are misconfigured and splunk servers are receiving traffic directly. For example the search head and indexer receiving traffic directly even if a syslog server/HF is present in the environment. Is there a search with which I can find out each source type and which Splunk  server is receiving the logs and forwarding it to the indexer layer. This will really help in resolving issues.

Thanks

 

0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @rabrahaham,

You can find your forwarders destinations using below search, normally you should not see an address other than indexer or heavy forwarder. 

index=_internal component=TcpOutputProc 
| stats count by idx

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.

richgalloway
SplunkTrust
SplunkTrust

Forwarding is transparent so there's no indication of where an event was forwarded from (unless you've taken actions to add something).

Check your search heads and indexers for inputs.conf files and remove any TCP or UDP inputs.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...