Splunk Search

Heavy Forwarder Search

fmcgheeSplunk
Splunk Employee
Splunk Employee

i have a need to search the HWF for the apps that are currently used frequently and also which apps are sending data to indexers. 

 

Context - Upgrade readiness app has identified several apps that are not supported or in need of upgrade. Need to see if these apps are needed any longer and can be removed or truly need to be upgraded prior to the Splunk version upgrade of the HWF. 

Labels (2)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Well, it's not apps that send data, it's your forwarders 😉

But seriously - for data originating on this forwarder, you can just check which inputs are enabled and which are disabled so you can at least verify which inputs are definitely "not needed. Unfortunately, maybe short of some heavy debug, there is not even possible to know which way the event passed through so if you have HF processing data from some set of UF unless you know which UF's are supposed to output to this particular HF, you can't tell it from the resulting indexed event.

Having said that - if you're asking in context of upgrading to python3 and we're talking about HF, you probably mean which modular inputs are in use. I'd just do a btool inputs list and check which ones are enabled.

Get Updates on the Splunk Community!

Blueprints for High-Maturity Operations: Splunk Lantern Articles on SOAR, ES 8.4, ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Simplifying the Analyst Experience with Finding-based Detections

    Splunk invites you to an engaging Tech Talk focused on streamlining security operations with ...

[Puzzles] Solve, Learn, Repeat: Word Search

This challenge was first posted on Slack #puzzles channelThis puzzle is based on a letter grid containing ...