Splunk Search

hosts event log lost behind a splunk forwarder

warmup031
Explorer

Hello,

We have had a forwarder that has its disk full several times in a weekend, So some hosts were not able to send their logs to this forwarder while splunk forwarder disk was full. how to list hosts (and know period for each host that sent no logs while this period. there are +100 hosts behind this forwarder, so a host=xxx | timechart count by host would not be efficient.

Thank you for your help

Tags (1)
0 Karma

warmup031
Explorer

Hello Giuseppe,

Many thanks for your reply. But is it possible (with "stats count" or timechart with span=1h), to get hosts with the less events or with zero events with span=1h for a day received by the forwarder ?

Thank you

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @warmup031,
using timechart, I think, it's the only way to highlight the periods when an host didn't send its logs,
I understand that if you have more than 100 hosts it's difficoult to read this diagram.
Eventually you could monitor disk space tracing the periods when it's 100%: they are the periods when you lost hosts's logs.

But maybe you could have a different approach creating an alert that warns you when the disk space on the forwarder is less than what is expected for the weekend (you surely be able to predict the needed disk space on Forwarder during week-end).

Ciao.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...