Can anyone please help me with the search to check for forwarder thruput and forwarder internal logs ( to see if there are any errors ) ?
Try this
Thruput logs (different thruput logs are available. check group field values in left field side bar)
index=_internal sourcetype=splunkd source=*metrics.log component=Metrics group=*thruput host=YourForwarderHostName
for internal Logs, just check
index=_internal sourcetype=splunkd log_level!=INFO
Thank you.. But i can't get the visualization for thruput logs.