I configured only 3 hosts as forwarders, but in App > Search & Reporting > Data Summary, I found more hosts and some of them are not configured as forwarders. Is possible that the Splunk server collects logs from hosts that are not configured as forwarders?
Thank you,
Egi
Hi etaga,
in inputs.conf
on your indexer you can use the acceptFrom = ...
option to restrict or allow connection. See the docs for more details http://docs.splunk.com/Documentation/Splunk/6.2.4/admin/inputsconf
cheers, MuS