Is there a way to check and see if a forward is actively forwarding?
For example, at one point splunk add forward-server <server>:<port> -auth <user>:<pass>
is executed, but then later splunk remove forward-server ...
is executed.
Is there a way to check that splunk is still forwarding other than looking at the indexer?
Thanks!
root@tf2:~# /opt/splunkforwarder/bin/splunk list forward-server
Active forwards:
None
Configured but inactive forwards:
forwarder.splunkstorm.com:9997
logs4.splunkstorm.com:20140
root@tf2:~#