Splunk search for Hosts forwarding internal logs to Indexers
Copy
index=_internal sourcetype=splunkd | stats dc(hostname) as "Unique Splunk Hosts"
This search will provide a count of the number of unique hosts that are forwarding their internal logs to Splunk. In practice this will be any instances that have an outputs.conf pointing to the indexer layer.