Getting Data In

How to verify if Splunk Forwarder is receiving the data on a UDP port

ssankeneni
Communicator

How can I verify if my universal forwarder is receiving the data on the UDP port ? I don't see any thing in my splunkd logs.

0 Karma

Ayn
Legend

Easiest is to run something like tcpdump, Wireshark or similar and see if traffic flows in on the port.

0 Karma

Ayn
Legend

index=_internal group=per_source_thruput series=udp:514

ssankeneni
Communicator

I don't have access to the machine to install any new rpms. Can you please let me know is there any way i could find it through Splunk.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...