Splunk search for List of hosts forwarding internal logs to Indexers

Copy
| tstats count as Count where index=_internal by host
This Splunk search uses the tstats command to provide a count of the number of unique hosts that are forwarding their internal logs to the Indexing layer. Essentially this search provides a list of all forwarders, it will also include any full Splunk instances (such as Search Heads) that are sending their internal logs o the indexers.
0 comments

Category:

General Splunk


Tags:

tstats Admin general internal

Search Commands:

Sign in or Register to submit a comment