<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is there a way to detect in Splunk if a server was removed or deleted? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Is-there-a-way-to-detect-in-Splunk-if-a-server-was-removed-or/m-p/256088#M9706</link>
    <description>&lt;P&gt;One option could be to ping the servers using a scripted input and index the output to Splunk. Then based on the output of the ping, you can detect if the servers is in network or not. &lt;/P&gt;</description>
    <pubDate>Tue, 17 May 2016 15:52:39 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2016-05-17T15:52:39Z</dc:date>
    <item>
      <title>Is there a way to detect in Splunk if a server was removed or deleted?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Is-there-a-way-to-detect-in-Splunk-if-a-server-was-removed-or/m-p/256087#M9705</link>
      <description>&lt;P&gt;Is there a way to detect in Splunk if a server was removed or deleted from the network? &lt;/P&gt;</description>
      <pubDate>Tue, 17 May 2016 13:44:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Is-there-a-way-to-detect-in-Splunk-if-a-server-was-removed-or/m-p/256087#M9705</guid>
      <dc:creator>cds2016</dc:creator>
      <dc:date>2016-05-17T13:44:18Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to detect in Splunk if a server was removed or deleted?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Is-there-a-way-to-detect-in-Splunk-if-a-server-was-removed-or/m-p/256088#M9706</link>
      <description>&lt;P&gt;One option could be to ping the servers using a scripted input and index the output to Splunk. Then based on the output of the ping, you can detect if the servers is in network or not. &lt;/P&gt;</description>
      <pubDate>Tue, 17 May 2016 15:52:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Is-there-a-way-to-detect-in-Splunk-if-a-server-was-removed-or/m-p/256088#M9706</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2016-05-17T15:52:39Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to detect in Splunk if a server was removed or deleted?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Is-there-a-way-to-detect-in-Splunk-if-a-server-was-removed-or/m-p/256089#M9707</link>
      <description>&lt;P&gt;@Somesoni2,&lt;BR /&gt;
Hi. The server is unreachable via ping. I am looking more towards who and when may have shut down the server. Any thoughts? &lt;/P&gt;</description>
      <pubDate>Tue, 17 May 2016 16:52:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Is-there-a-way-to-detect-in-Splunk-if-a-server-was-removed-or/m-p/256089#M9707</guid>
      <dc:creator>cds2016</dc:creator>
      <dc:date>2016-05-17T16:52:32Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to detect in Splunk if a server was removed or deleted?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Is-there-a-way-to-detect-in-Splunk-if-a-server-was-removed-or/m-p/256090#M9708</link>
      <description>&lt;P&gt;You can set up a &lt;CODE&gt;scripted input&lt;/CODE&gt; to ping the forwarder (there are apps on Splunkbase for this) and setup an alert to let you know when any server is unreachable for a period of time.  Also setup &lt;CODE&gt;splunk WinEventLog://Security&lt;/CODE&gt; from the servers to be forwarded into Splunk.  Then you should be able to see the last person to login to that server, who should be the one who shut it down.&lt;/P&gt;</description>
      <pubDate>Sun, 29 May 2016 13:09:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Is-there-a-way-to-detect-in-Splunk-if-a-server-was-removed-or/m-p/256090#M9708</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2016-05-29T13:09:22Z</dc:date>
    </item>
  </channel>
</rss>

