Reader small image

You're reading from  Splunk 9.x Enterprise Certified Admin Guide

Product typeBook
Published inAug 2023
PublisherPackt
ISBN-139781803230238
Edition1st Edition
Right arrow
Author (1)
Srikanth Yarlagadda
Srikanth Yarlagadda
author image
Srikanth Yarlagadda

Srikanth is a highly accomplished IT professional with a diverse range of expertise in the technology industry. Having completed his Masters in Computer Applications in 2009, he has since honed his skills in Java, Oracle SOA, and API development, gaining valuable experience along the way. With over 13 years of experience in the field, Srikanth is now a Splunk Certified Architect and was recently selected to join the esteemed cohort of SplunkTrust in 2022. He has extensive knowledge of various Splunk products, including Splunk Enterprise Security and SOAR, and he is currently dedicated to Threat Detection and Security Automation using Splunk ES & SOAR. Srikanth's impressive work history includes significant roles at major telecom companies across Norway and Pan Europe. Beyond technology, Srikanth's greatest joy is his family. Along with his wife and two children, he calls Australia home and enjoys spending time together while staying active.
Read more about Srikanth Yarlagadda

Right arrow

Forwarder monitoring

Monitoring our setup is quite important as the number of forwarders grows, and it can sometimes be very challenging. To aid with this, Splunk offers the out-of-the-box MC app, which contains a dashboard to monitor the forwarders.

By default, the forwarder monitoring feature is disabled in MC and must be enabled by following these steps:

  1. Log in to the MC-dedicated Splunk instance and navigate to Settings | Monitoring Console.
  2. Inside Monitoring Console, go to Settings | Forwarding Monitoring Setup; you will find that it is disabled. Click Enable. By default, Data Collection Interval is set to 15 minutes; leave it as-is and click Save, as shown in Figure 4.5:
Figure 4.5: Forwarder Monitoring Setup

Figure 4.5: Forwarder Monitoring Setup

You will find two menu items under the Forwarders tab: Forwarders Instance and Forwarders Deployment, as shown in Figure 4.6. The Forwarders: Instance and Forwarders: Deployment dashboards are built on the internal logs of...

lock icon
The rest of the page is locked
Previous PageNext Page
You have been reading a chapter from
Splunk 9.x Enterprise Certified Admin Guide
Published in: Aug 2023Publisher: PacktISBN-13: 9781803230238

Author (1)

author image
Srikanth Yarlagadda

Srikanth is a highly accomplished IT professional with a diverse range of expertise in the technology industry. Having completed his Masters in Computer Applications in 2009, he has since honed his skills in Java, Oracle SOA, and API development, gaining valuable experience along the way. With over 13 years of experience in the field, Srikanth is now a Splunk Certified Architect and was recently selected to join the esteemed cohort of SplunkTrust in 2022. He has extensive knowledge of various Splunk products, including Splunk Enterprise Security and SOAR, and he is currently dedicated to Threat Detection and Security Automation using Splunk ES & SOAR. Srikanth's impressive work history includes significant roles at major telecom companies across Norway and Pan Europe. Beyond technology, Srikanth's greatest joy is his family. Along with his wife and two children, he calls Australia home and enjoys spending time together while staying active.
Read more about Srikanth Yarlagadda