Skip to main content
Warning
This app is archived. App archiving documentation
Forwarder toolbox - TA-forwarderquery app icon

Forwarder toolbox - TA-forwarderquery

Custom command to query a forwarder via its rest endpoint.Built by Dominique Vocat
splunk product badge

Default Version 0.7

October 30, 2017

Compatibility

Splunk Enterprise

Rating
5
(2)

Log in to rate this app

Support
Archived Add-on

Custom command to query a forwarder via its rest endpoint. Ever wanted to easily inspect the settings on your forwarders like which indexers receive the data, what apps are installed and which inputs do they provide? Even if you are not able to connect yourself to the machine because you are not admin of the Linux, Windows etc Servers? This TA provides you with the means to specify the user and password for the forwarder REST access and allows you to do just that. Plus it comes with a nice Dashboard to browse through your forwarders. Alas the built in | rest command will not allow you to connect to a forwarder so this is effectively a workaround. See also http://answers.splunk.com/answers/229173/forwarder-rest-api-how-can-i-get-the-list-of-files.html for the rationale. Usually you would install it on the deployment server and have a firewall rule to open port 8089 on all forwarders etc from this server.