I'm trying to produce an architecture diagram of our Splunk environment and I want to know what each of our universal forwarders and heavy forwarders are ingesting and sending. I'm looking in inputs and outputs.conf but they are of no use. Is there a way to view what each forwarder is ingesting and sending, whether that be via the command line or in Splunk itself?
Hi @jhilton90,
with the host field you should have the Universal Forwarder hostname, unless you manually configured a different host (e.g. when you're reading files in a syslog server).
Ciao.
Giuseppe
Thanks Giuseppe,
How do I actually go about finding out what local logs it's reading?
Hi @jhilton90 ,
good for you, see next time!
Ciao and happy splunking
Giuseppe
P.S.: Karma Points are appreciated 😉
Hi @jhilton90,
with the host field you should have the Universal Forwarder hostname, unless you manually configured a different host (e.g. when you're reading files in a syslog server).
Ciao.
Giuseppe
Hi @jhilton90,
you can have the information about the UF only if it's reading the local logs, otherwise you cannot have this information and never about HFs.
I asked this feature to Splunk Ideas (https://ideas.splunk.com/ideas/EID-I-1731) and it's "Under consideration", if you're interested, vote for it!
Ciao.
Giuseppe
Upvoted!