Splunk Search

Search for events from a certain universal forwarder

peter_gianusso
Communicator

I have 2 universal forwarders sending data to 1 indexer. I want to search to see if one of the universal forwarders is actually sending data. How would I do that?

0 Karma

somesoni2
Revered Legend

something like this should work. If you get any result means forwarders are sending data.

index=IndexWhereForwSendingData host=yourhost1 OR host=yourhost2

lukejadamec
Super Champion

Typically the forwarder sends information which can be identified with the host field. So, search for everything, and you should see two hosts.

Yankees suck.

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In January, the Splunk Threat Research Team had one release of new security content via the Splunk ES Content ...

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...