Splunk Search
Highlighted

How to generate a search to check forwarder thruput and internal logs?

Path Finder

Can anyone please help me with the search to check for forwarder thruput and forwarder internal logs ( to see if there are any errors ) ?

0 Karma
Highlighted

Re: How to generate a search to check forwarder thruput and internal logs?

SplunkTrust
SplunkTrust

Try this

Thruput logs (different thruput logs are available. check group field values in left field side bar)

index=_internal sourcetype=splunkd source=*metrics.log component=Metrics group=*thruput host=YourForwarderHostName 

for internal Logs, just check

index=_internal sourcetype=splunkd log_level!=INFO
0 Karma
Highlighted

Re: How to generate a search to check forwarder thruput and internal logs?

Path Finder

Thank you.. But i can't get the visualization for thruput logs.

0 Karma