Splunk search for List of hosts forwarding internal logs to Indexers
Copy
| tstats count as Count where index=_internal by host
This Splunk search uses the tstats command to provide a count of the number of unique hosts that are forwarding their internal logs to the Indexing layer. Essentially this search provides a list of all forwarders, it will also include any full Splunk instances (such as Search Heads) that are sending their internal logs o the indexers.