Deployment Architecture

how to find forwarders in which splunk boot-start is enabled ?

nilbak1
Communicator

I want to find the splunk forwarders in which boot script is enabled.
Is there any query ?

0 Karma
1 Solution

ansif
Motivator

I don't know the query. If you find any log files that logs boot start then you can use that log file to search.

Rather you can use scripts to determine if boot start enabled or NOT.

For Windows forwarders use Powershell script to get Splunk service startup status.

Linux machines use shell script to check if Sxxsplunk link file exist under /etc/rc.d/rc3.d (example S90splunk )

Both scripts use your servernames as input.

View solution in original post

0 Karma

ansif
Motivator

I don't know the query. If you find any log files that logs boot start then you can use that log file to search.

Rather you can use scripts to determine if boot start enabled or NOT.

For Windows forwarders use Powershell script to get Splunk service startup status.

Linux machines use shell script to check if Sxxsplunk link file exist under /etc/rc.d/rc3.d (example S90splunk )

Both scripts use your servernames as input.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...