Splunk Enterprise

powershell command to check if splunk is forwarding logs to splunk console

LinkLoop
Engager

Is there a powershell command to find out if splunk is indeed forwarding logs to splunk console? I can check if agent is installed andrunning but how about forwarding?

 

which log should i check for?

Labels (2)
0 Karma

tscroggins
Champion

Hi @LinkLoop,

You can verify Splunk is connected to outputs with the list forward-server command:

& "C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe" list forward-server -auth admin:password

Active forwards:
        splunk.example.com:9997 (ssl)
Configured but inactive forwards:
        None

The command requires authentication, so you'll need to know the local Splunk admin username and password defined at install time.

If the local management port is disabled, the command will not be available. You can otherwise search local logs for forwarding activity:

Select-String -Path "C:\Program Files\SplunkUniversalForwarder\var\log\splunk\splunkd.log" -Pattern "Connected to idx="

Select-String -Path "C:\Program Files\SplunkUniversalForwarder\var\log\splunk\metrics.log" -Pattern "group=per_index_thruput, series=`"_internal`""

 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...