Hello!
Recently noticed some universal forwarders hang and not sending logs to indexer. So, how I can monitor my Splunk universal forwarder sending logs to make sure the forwarder is working as expected. I have `index="_internal"`, but is there any search to help me to create a dashboard or alert?
↧
How I can monitor my Splunk universal forwarder to make sure the forwarder is working as expected?
↧