Splunk searches relating to Universal Forwarder
clear
index=_internal sourcetype=splunkd (alert_description="'certificate expired'" component=SSLCommon) OR (component=TcpInputProc AND "certificate verify failed")
index=_internal sourcetype=splunkd "TailReader - File descriptor cache is full" "trimming" | stats count by host
index=_internal tcpouteloop "connected to idx" | stats count by idx