Splunk Search

Search for events from a certain universal forwarder

peter_gianusso
Communicator

I have 2 universal forwarders sending data to 1 indexer. I want to search to see if one of the universal forwarders is actually sending data. How would I do that?

0 Karma

somesoni2
Revered Legend

something like this should work. If you get any result means forwarders are sending data.

index=IndexWhereForwSendingData host=yourhost1 OR host=yourhost2

lukejadamec
Super Champion

Typically the forwarder sends information which can be identified with the host field. So, search for everything, and you should see two hosts.

Yankees suck.

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...