Splunk Search

Search for events from a certain universal forwarder


I have 2 universal forwarders sending data to 1 indexer. I want to search to see if one of the universal forwarders is actually sending data. How would I do that?

0 Karma

Revered Legend

something like this should work. If you get any result means forwarders are sending data.

index=IndexWhereForwSendingData host=yourhost1 OR host=yourhost2

Super Champion

Typically the forwarder sends information which can be identified with the host field. So, search for everything, and you should see two hosts.

Yankees suck.

Get Updates on the Splunk Community!

How I Instrumented a Rust Application Without Knowing Rust

As a technical writer, I often have to edit or create code snippets for Splunk's distributions of ...

Splunk Community Platform Survey

Hey Splunk Community, Starting today, the community platform may prompt you to participate in a survey. The ...

Observability Highlights | November 2022 Newsletter

 November 2022Observability CloudEnd Of Support Extension for SignalFx Smart AgentSplunk is extending the End ...