Splunk Search

Heavy Forwarder Search

fmcgheeSplunk
Splunk Employee
Splunk Employee

i have a need to search the HWF for the apps that are currently used frequently and also which apps are sending data to indexers. 

 

Context - Upgrade readiness app has identified several apps that are not supported or in need of upgrade. Need to see if these apps are needed any longer and can be removed or truly need to be upgraded prior to the Splunk version upgrade of the HWF. 

Labels (3)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Well, it's not apps that send data, it's your forwarders 😉

But seriously - for data originating on this forwarder, you can just check which inputs are enabled and which are disabled so you can at least verify which inputs are definitely "not needed. Unfortunately, maybe short of some heavy debug, there is not even possible to know which way the event passed through so if you have HF processing data from some set of UF unless you know which UF's are supposed to output to this particular HF, you can't tell it from the resulting indexed event.

Having said that - if you're asking in context of upgrading to python3 and we're talking about HF, you probably mean which modular inputs are in use. I'd just do a btool inputs list and check which ones are enabled.

Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...