Splunk Search

How can I search for list of UF's and to which index they are sending data to ?

AK007
Engager

Hi, 

Want to find universal forwarders and to which index they are sending data to ?

We have cmd to list all the UF. Need help on how to check/co-relate internal logs to which index they are sending data to. 

Labels (4)
0 Karma

thambisetty
Super Champion
| tstats count  where index=_* OR index=*  by host,index
| stats values(index) as index dc(index) as distinct_count by host
| sort - distinct_count
————————————
If this helps, give a like below.
0 Karma

gcusello
Legend

Hi @AK007,

to know the indexes where logs are stored you can run a simple search:

 

| metasearch index=*
| stats values(index) AS index count BY host

 

if you want also internal indexes:

 

| metasearch index=* OR index=_*
| stats values(index) AS index count BY host

 

In addition, if you want to check if all the UFs are sending logs, you can insert the UFs to monitor in a lookup and run a search like this:

| metasearch index=* OR index=_*
| eval host=lower(host)
| stats values(index) AS index count BY host
| append [ | inputlookup my_lookup | eval host=lower(host), count=0 | fields count host ]
| stats values(index) AS index sum(count) AS total BY host

in this way, the hosts with total=0 aren't sending logs and they are missed.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Routing Data to Different Splunk Indexes in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

Getting Started with AIOps: Event Correlation Basics and Alert Storm Detection in ...

Getting Started with AIOps:Event Correlation Basics and Alert Storm Detection in Splunk IT Service ...

Register to Attend BSides SPL 2022 - It's all Happening October 18!

Join like-minded individuals for technical sessions on everything Splunk!  This is a community-led and run ...