Is there a way to check and see if a forward is actively forwarding?
For example, at one point splunk add forward-server <server>:<port> -auth <user>:<pass> is executed, but then later splunk remove forward-server ... is executed.
Is there a way to check that splunk is still forwarding other than looking at the indexer?
... View more