Hi All,
I am relatively new to Splunk, In my environment we are using deployment server to manage the deployment apps on universal forwarders.
During the installation of universal forwarders, we specify the deployment server in deployment.conf.
But we have not mentioned anything about forwarding the data to the heavy forwarder (HF).
On the web interface of our heavy forwarders, under forwarding and receiving, I cannot see any configuration set up.
How can I check whether universal forwarders are sending data to HF? Are indexers or data getting managed by the deployment server?
I don't have access to the universal forwarders as these are managed by some different team.
So I have to check the configuration within the HF, Indexer or deployment servers.
Regards
Rohit
↧