Splunk Search

Heavy Forwarder Search

fmcgheeSplunk
Splunk Employee
Splunk Employee

i have a need to search the HWF for the apps that are currently used frequently and also which apps are sending data to indexers. 

 

Context - Upgrade readiness app has identified several apps that are not supported or in need of upgrade. Need to see if these apps are needed any longer and can be removed or truly need to be upgraded prior to the Splunk version upgrade of the HWF. 

Labels (3)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Well, it's not apps that send data, it's your forwarders 😉

But seriously - for data originating on this forwarder, you can just check which inputs are enabled and which are disabled so you can at least verify which inputs are definitely "not needed. Unfortunately, maybe short of some heavy debug, there is not even possible to know which way the event passed through so if you have HF processing data from some set of UF unless you know which UF's are supposed to output to this particular HF, you can't tell it from the resulting indexed event.

Having said that - if you're asking in context of upgrading to python3 and we're talking about HF, you probably mean which modular inputs are in use. I'd just do a btool inputs list and check which ones are enabled.

Get Updates on the Splunk Community!

Harnessing Splunk’s Federated Search for Amazon S3

Managing your data effectively often means balancing performance, costs, and compliance. Splunk’s Federated ...

Infographic provides the TL;DR for the 2024 Splunk Career Impact Report

We’ve been buzzing with excitement about the recent validation of Splunk Education! The 2024 Splunk Career ...

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...