I have asked to Add the new Linux HFs to the forwarding configurations and ensure that logs are passing through them
how to verify the condition is met or not
Hi @umeshcreddy,
let me understand:
in the first case run on Search Heads the following search:
(index=_internal OR index=*) host=HF_hostname
If instead your HF is a concentrator and you want to know if logs are passing, list the hosts that are sending logs anche check if there are the correct list of hosts with a simple search on Search Heads:
index=_internal OR index=*
| stats count BY host
Ciao.
Giuseppe
Hi @umeshcreddy,
let me understand:
in the first case run on Search Heads the following search:
(index=_internal OR index=*) host=HF_hostname
If instead your HF is a concentrator and you want to know if logs are passing, list the hosts that are sending logs anche check if there are the correct list of hosts with a simple search on Search Heads:
index=_internal OR index=*
| stats count BY host
Ciao.
Giuseppe
@gcusello cant we check in the deployment sever in the forwarder management for the HF_hostname whether deployed or not. I have this doubt can you please confirm
Hi @umeshcreddy,
to check if HF was deployed by Deployment Server is a different thing: it's not relevant Ds to understand if an HF is logging or not.
Ciao and happy splunking.
Giuseppe
P.S. Karma Points are appreciated 😉