I have splunk forwarders configured on 3 machines going to a splunk receiver. I have a request to create a real-time dashboard.
My question is why I can only see events from one of the forwarders when I do a 30 second window real-time search. Is there something configured in the forwarder that enables/disables rt search?
This is most likely caused by time skew on the two forwarders that are not being reported. The time window is the most recent 30s relative to the clock on the node that you're doing the search from. To confirm this, you can run a search over all-time real-time like:
index=* | eval lag = _time-_indextime | stats min(lag) max(lag) by host