<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using Splunk as a monitoring tool in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Using-Splunk-as-a-monitoring-tool/m-p/316444#M5274</link>
    <description>&lt;P&gt;That's great!&lt;/P&gt;

&lt;P&gt;So, for example, could we monitor:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Number of TCP Connections for a server&lt;/LI&gt;
&lt;LI&gt;Parse the logs to identify the number of open connections&lt;/LI&gt;
&lt;LI&gt; Specific errors&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;...and have, say, the number of TCP connections displayed in a graph format (e.g. time vs number of connections)? And we don't need the REST API to do that, we can just write that ourselves?&lt;/P&gt;

&lt;P&gt;Any ideas on how to get started?&lt;/P&gt;</description>
    <pubDate>Tue, 11 Apr 2017 05:56:43 GMT</pubDate>
    <dc:creator>Alexw1900</dc:creator>
    <dc:date>2017-04-11T05:56:43Z</dc:date>
    <item>
      <title>Using Splunk as a monitoring tool</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Using-Splunk-as-a-monitoring-tool/m-p/316442#M5272</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;

&lt;P&gt;We currently run an on-prem application with the following tiers;&lt;/P&gt;

&lt;P&gt;Client - App servers - Database servers&lt;/P&gt;

&lt;P&gt;The App servers are Windows 2012, the Database is SQL 2008 on Windows 2012.&lt;/P&gt;

&lt;P&gt;At the moment, we have a bespoke monitoring tool that ingests logs from the App/Database servers and displays the pertinent information graphically on a web interface. We have also set up alerts for specific log entries.&lt;/P&gt;

&lt;P&gt;Our organisations uses SPLUNK so I was thinking of a way of ingesting the logs to a SPLUNK repository and then writing a custom tool that could display the same information. This way, we can decomm one more bespoke monitoring platform.&lt;/P&gt;

&lt;P&gt;Has anyone had any experience of this or point me in the right direction? I understand that SPLUNK has Rest API's to hook into that I'm hoping can help.&lt;/P&gt;</description>
      <pubDate>Sun, 09 Apr 2017 19:55:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Using-Splunk-as-a-monitoring-tool/m-p/316442#M5272</guid>
      <dc:creator>Alexw1900</dc:creator>
      <dc:date>2017-04-09T19:55:31Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk as a monitoring tool</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Using-Splunk-as-a-monitoring-tool/m-p/316443#M5273</link>
      <description>&lt;P&gt;Welcome to the real monitoring tool mate :). We have used Splunk as monitoring tool for 1000's of systems and have got near real time data and alerting&lt;/P&gt;

&lt;P&gt;Well, you can use Splunk to any level of monitoring. You don't need to write any kind of custom tool in my opinion nor REST api, once you see the data. Few options for you&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Get all the data for your application into Splunk (Using Splunk Universal Forwader OR syslog or DBconnect or any other methods)&lt;/LI&gt;
&lt;LI&gt;Write searches and dashboards to view what you requite for monitoring&lt;/LI&gt;
&lt;LI&gt;Write searches and alerts to alert you&lt;/LI&gt;
&lt;LI&gt;Create reports for your team and management&lt;/LI&gt;
&lt;LI&gt;If you require service modelling (impact analysis based approach) lot of free apps are available within splunk. Or there is official ITSI app which can do all wonders&lt;/LI&gt;
&lt;LI&gt;if none of above is sufficient you can look into REST api or custom tool.&lt;/LI&gt;
&lt;LI&gt;Any queries/help with searches post in this forum&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Sun, 09 Apr 2017 21:33:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Using-Splunk-as-a-monitoring-tool/m-p/316443#M5273</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2017-04-09T21:33:16Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk as a monitoring tool</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Using-Splunk-as-a-monitoring-tool/m-p/316444#M5274</link>
      <description>&lt;P&gt;That's great!&lt;/P&gt;

&lt;P&gt;So, for example, could we monitor:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Number of TCP Connections for a server&lt;/LI&gt;
&lt;LI&gt;Parse the logs to identify the number of open connections&lt;/LI&gt;
&lt;LI&gt; Specific errors&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;...and have, say, the number of TCP connections displayed in a graph format (e.g. time vs number of connections)? And we don't need the REST API to do that, we can just write that ourselves?&lt;/P&gt;

&lt;P&gt;Any ideas on how to get started?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2017 05:56:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Using-Splunk-as-a-monitoring-tool/m-p/316444#M5274</guid>
      <dc:creator>Alexw1900</dc:creator>
      <dc:date>2017-04-11T05:56:43Z</dc:date>
    </item>
  </channel>
</rss>

