Splunk Search

Search for events from a certain universal forwarder

peter_gianusso
Communicator

I have 2 universal forwarders sending data to 1 indexer. I want to search to see if one of the universal forwarders is actually sending data. How would I do that?

0 Karma

somesoni2
Revered Legend

something like this should work. If you get any result means forwarders are sending data.

index=IndexWhereForwSendingData host=yourhost1 OR host=yourhost2

lukejadamec
Super Champion

Typically the forwarder sends information which can be identified with the host field. So, search for everything, and you should see two hosts.

Yankees suck.

Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

  Ready to master Kubernetes and cloud monitoring like the pros?Join Splunk’s Growth Engineering team for an ...

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...