<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to monitor servers using splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-monitor-servers-using-splunk/m-p/371676#M67461</link>
    <description>&lt;P&gt;First step is to collect the relevant data from the logs (I assume). The moment you have the data, you can work on the alerts. &lt;/P&gt;</description>
    <pubDate>Mon, 02 Oct 2017 18:07:29 GMT</pubDate>
    <dc:creator>ddrillic</dc:creator>
    <dc:date>2017-10-02T18:07:29Z</dc:date>
    <item>
      <title>How to monitor servers using splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-monitor-servers-using-splunk/m-p/371673#M67458</link>
      <description>&lt;P&gt;I have been tasked with figuring out how to monitor server activity using splunk and create alerts&lt;/P&gt;</description>
      <pubDate>Mon, 02 Oct 2017 15:38:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-monitor-servers-using-splunk/m-p/371673#M67458</guid>
      <dc:creator>2powder</dc:creator>
      <dc:date>2017-10-02T15:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to monitor servers using splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-monitor-servers-using-splunk/m-p/371674#M67459</link>
      <description>&lt;P&gt;Could you provide more details on what you mean by "server activity"?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Oct 2017 15:55:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-monitor-servers-using-splunk/m-p/371674#M67459</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2017-10-02T15:55:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to monitor servers using splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-monitor-servers-using-splunk/m-p/371675#M67460</link>
      <description>&lt;P&gt;For example, let's say that we have 10 servers that all run the same code.  The traffic is load balanced and the code performs a process, that either completes successfully.  At the end of the process there is a flag that is set such as "Successful = yes or no".  There is also a couple of identifiers such as the vendor ie.  "ABC Company" and then there is a unique "Process ID".   This process is called real time 24/7.  What I am looking for is an alert that will alert me (and others) when a certain threshold has been exceeded.   For example, for ABC Company if the Successful = no count &amp;lt; 5 during a certain time period then no alert, but as soon as it goes over 5, then I am alerted.&lt;/P&gt;

&lt;P&gt;I hope that this helped.&lt;/P&gt;

&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 02 Oct 2017 17:31:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-monitor-servers-using-splunk/m-p/371675#M67460</guid>
      <dc:creator>2powder</dc:creator>
      <dc:date>2017-10-02T17:31:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to monitor servers using splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-monitor-servers-using-splunk/m-p/371676#M67461</link>
      <description>&lt;P&gt;First step is to collect the relevant data from the logs (I assume). The moment you have the data, you can work on the alerts. &lt;/P&gt;</description>
      <pubDate>Mon, 02 Oct 2017 18:07:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-monitor-servers-using-splunk/m-p/371676#M67461</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2017-10-02T18:07:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to monitor servers using splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-monitor-servers-using-splunk/m-p/371677#M67462</link>
      <description>&lt;P&gt;That information is already being collected&lt;/P&gt;</description>
      <pubDate>Mon, 02 Oct 2017 20:43:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-monitor-servers-using-splunk/m-p/371677#M67462</guid>
      <dc:creator>2powder</dc:creator>
      <dc:date>2017-10-02T20:43:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to monitor servers using splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-monitor-servers-using-splunk/m-p/371678#M67463</link>
      <description>&lt;P&gt;maybe this video about creating alerts will help &lt;A href="https://www.youtube.com/watch?annotation_id=annotation_2942967387&amp;amp;feature=iv&amp;amp;src_vid=SuARLqm7_jc&amp;amp;v=0REbozaALX0" target="_blank"&gt;https://www.youtube.com/watch?annotation_id=annotation_2942967387&amp;amp;feature=iv&amp;amp;src_vid=SuARLqm7_jc&amp;amp;v=0REbozaALX0&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:04:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-monitor-servers-using-splunk/m-p/371678#M67463</guid>
      <dc:creator>davebrooking</dc:creator>
      <dc:date>2020-09-29T16:04:38Z</dc:date>
    </item>
  </channel>
</rss>

