Splunk Search

forwarder

SN1
Path Finder

Hello I have a index name msad and i want to know which forwarder is sending data to this index . And also the data it is sending is stored where like from where this forwarder is sending this data.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

The general answer to questions like "how to find which hosts send to which indexes" is "you can't do that reliably". There are some things you can do to find info in some specific situations but they will not cover all possible scenarios.

1. As @livehybrid already pointed out, you can try browsing through forwarders' metrics. There are two caveats here:

- the metrics are limited to a fixed number of top data points so if your forwarder is sending to a huge number of different indexes you might not see that

- events can be rerouted on HFs/indexers to different indexes that they were initially destined for

2. You can simply check the host field. But this is very unreliable technique and only works if you're capturing the events localy with the forwarder and not override the host in any way.

3. You can configure your environment (but this needs to be beforehand) so that forwarders add metadata to events by means of additional indexed fields or - for some types of sources - source field. This might get complicated and difficult to maintain if you don't use orchestration tools. And might have limitations if you're using multi-hop ingestion paths.

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @SN1 

You can modify the search below to use the metrics.log to get this information, update the series= value with the index name you want to look at, and you may also want to exclude your indexer(s) as these also collect the metrics on index thruput

index=_internal series=YourIndex group=per_index_thruput host!=YourIndexer* 
|  eval gb=kb/1024/1024
|  timechart sum(gb) AS gb by host 

This will give a chart showing the GB of data for each forwarder.

livehybrid_0-1738748815198.png

Please let me know how you get on and consider upvoting/karma this answer if it has helped.
Regards

Will

 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...