Splunk Search

hosts event log lost behind a splunk forwarder

warmup031
Explorer

Hello,

We have had a forwarder that has its disk full several times in a weekend, So some hosts were not able to send their logs to this forwarder while splunk forwarder disk was full. how to list hosts (and know period for each host that sent no logs while this period. there are +100 hosts behind this forwarder, so a host=xxx | timechart count by host would not be efficient.

Thank you for your help

Tags (1)
0 Karma

warmup031
Explorer

Hello Giuseppe,

Many thanks for your reply. But is it possible (with "stats count" or timechart with span=1h), to get hosts with the less events or with zero events with span=1h for a day received by the forwarder ?

Thank you

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @warmup031,
using timechart, I think, it's the only way to highlight the periods when an host didn't send its logs,
I understand that if you have more than 100 hosts it's difficoult to read this diagram.
Eventually you could monitor disk space tracing the periods when it's 100%: they are the periods when you lost hosts's logs.

But maybe you could have a different approach creating an alert that warns you when the disk space on the forwarder is less than what is expected for the weekend (you surely be able to predict the needed disk space on Forwarder during week-end).

Ciao.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...