Hi!
I need to find out list of all the servers where **splunkd service is not running** which were running before. I have more than 9000 forwarders and have three scenarios which are listed below:
1. splunkd is not running.
2. splunkd is running and deployment client is set but indexer configurations are not done.
3. splunkd is running and indexer configurations are done but deployment client is not set.
Because of the above limitations, I am finding it difficult to use queries which are based on phone home or internal logs received in Splunk as its showing up incorrect server list.
Also, I'm not allowed to use script to monitor the splunkd service on each hosts as it requires remote login.
Thank You.
↧