Monitoring Splunk

How to know all integrated forwarders within the environment?

aasserhifni
Loves-to-Learn Everything

I see different forwarders count using the following different ways:

  1. Looking at the forwarder management at the license master
  2. Looking at the Forwarders:Deployment at the license master
  3. Looking at  dmc_forwarder_assets.csv inside /opt/splunk/etc/apps/splunk_monitoring_console/lookups/  at the license master

So, which one should I guarantee and is there any better way?

Labels (2)
0 Karma

deepakc
Builder

From the MC run the below - it should give you a starting point

index=_internal source=*metrics.log group=tcpin_connections fwdType=uf hostname=* | eval hostname=lower(hostname)  
| fields _time hostname sourceIp arch destPort fwdType os ssl version
| table _time hostname sourceIp arch destPort fwdType os ssl version
|  dedup hostname
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...