<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to get instance health via splunk query in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-get-instance-health-via-splunk-query/m-p/358193#M5558</link>
    <description>&lt;P&gt;Thanks Harshil it worked for me.&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Santosh.&lt;/P&gt;</description>
    <pubDate>Tue, 14 Nov 2017 08:51:55 GMT</pubDate>
    <dc:creator>santosh12</dc:creator>
    <dc:date>2017-11-14T08:51:55Z</dc:date>
    <item>
      <title>How to get instance health via splunk query</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-get-instance-health-via-splunk-query/m-p/358190#M5555</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;I have 10 instances running 3 search head, 3 indexer, 1 monitoring console, 1 license manager, 1 deployment manager and 1 index master. How can we get all the instances and there status whether they are up and running or they are down via splunk query?&lt;/P&gt;

&lt;P&gt;I know we can check in monitoring console but we need via query.&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Santosh.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2017 11:23:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-get-instance-health-via-splunk-query/m-p/358190#M5555</guid>
      <dc:creator>santosh12</dc:creator>
      <dc:date>2017-11-09T11:23:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to get instance health via splunk query</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-get-instance-health-via-splunk-query/m-p/358191#M5556</link>
      <description>&lt;P&gt;Hi @santosh12,&lt;/P&gt;

&lt;P&gt;You can use below query that I have created based on DMC query but it will work from DMC server only because from one search head you can't run rest query of other heads, cluster master, deployment server.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| rest splunk_server=local /services/search/distributed/peers | rename title as peerURI  | join type=outer peerURI [| rest splunk_server=local /services/server/info | eval peerURI = "localhost" | eval status = "Up"]  | eval status = if(status == "Up", status, "Unreachable") | eval OS = os_name | eval ram = round(physicalMemoryMB / 1024, 2)." GB" | fields host, server_roles, OS, numberOfCores, ram, version, status| sort status, host| rename host as Instance, server_roles as Role, numberOfCores as "Cores", ram as RAM, version as Version, status as Status
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I hope this helps.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Harshil&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2017 12:30:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-get-instance-health-via-splunk-query/m-p/358191#M5556</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2017-11-09T12:30:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to get instance health via splunk query</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-get-instance-health-via-splunk-query/m-p/358192#M5557</link>
      <description>&lt;P&gt;I don't have an idea about this idea I am a student and currently working in Australian.So many stress because I have an &lt;A href="https://www.australianassignmentshelp.com/"&gt;assignment writing service&lt;/A&gt; leading firm.But this idea helps me for making an assignment.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2017 12:39:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-get-instance-health-via-splunk-query/m-p/358192#M5557</guid>
      <dc:creator>shaunpaul</dc:creator>
      <dc:date>2017-11-09T12:39:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to get instance health via splunk query</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-get-instance-health-via-splunk-query/m-p/358193#M5558</link>
      <description>&lt;P&gt;Thanks Harshil it worked for me.&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Santosh.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2017 08:51:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-get-instance-health-via-splunk-query/m-p/358193#M5558</guid>
      <dc:creator>santosh12</dc:creator>
      <dc:date>2017-11-14T08:51:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to get instance health via splunk query</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-get-instance-health-via-splunk-query/m-p/358194#M5559</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
to display the localhost entry, you must use append instead of outer join since left and outer are the same thing in splunk.&lt;BR /&gt;
See  doc: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.1/SearchReference/Join"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.1/SearchReference/Join&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 May 2018 10:27:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-get-instance-health-via-splunk-query/m-p/358194#M5559</guid>
      <dc:creator>emafront</dc:creator>
      <dc:date>2018-05-04T10:27:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to get instance health via splunk query</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-get-instance-health-via-splunk-query/m-p/358195#M5560</link>
      <description>&lt;P&gt;It works from search head, Splunk Enterprise V7.1.4&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2019 22:38:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-get-instance-health-via-splunk-query/m-p/358195#M5560</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2019-06-18T22:38:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to get instance health via splunk query</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-get-instance-health-via-splunk-query/m-p/552881#M5561</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I don't know, because I'm not professional in this area. I am a student and I have complicated task. I'm ready to buy a&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://custom-paper-writing.org/write-my-coursework-please" target="_self"&gt;&lt;SPAN&gt;coursework&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;paper from reliable writing company.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 May 2021 06:42:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-get-instance-health-via-splunk-query/m-p/552881#M5561</guid>
      <dc:creator>MargoAdams</dc:creator>
      <dc:date>2021-05-25T06:42:11Z</dc:date>
    </item>
  </channel>
</rss>

