<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk End TO End Monitoring ? in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-End-TO-End-Monitoring/m-p/160863#M7827</link>
    <description>&lt;P&gt;I'm trying to develop something similar, would love to see what you have so far if possible?&lt;/P&gt;</description>
    <pubDate>Wed, 26 Aug 2015 18:29:43 GMT</pubDate>
    <dc:creator>dmerritt77</dc:creator>
    <dc:date>2015-08-26T18:29:43Z</dc:date>
    <item>
      <title>Splunk End TO End Monitoring ?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-End-TO-End-Monitoring/m-p/160862#M7826</link>
      <description>&lt;P&gt;Hi All ,&lt;/P&gt;

&lt;P&gt;I have developed a mini POC to look out for Splunk End to End Monitoring . The POC will be triggered if there is a missing log source being reported in the splunk alert. Below are my checks and i would like to know that whether i have missed any checks ?&lt;/P&gt;

&lt;P&gt;Main Query : Splunk Query for missing log sources. This will trigger the below steps:&lt;BR /&gt;
 1. Splunk Connection to Search Head&lt;BR /&gt;
 1.a If splunk connection fails then check for network connection to Search head instance by a 'ping', followed by a health check on ports and services.&lt;BR /&gt;
 2. If connection is successfull, Splunk Query to check whether all indexers are reporting for last say 60 mins.&lt;BR /&gt;
 2.a if some of indexers are not reporting then, check for network connection to indexers with a ping followed by a  health check on ports and services.&lt;BR /&gt;
 3. If connection is successfull , then Splunk query to check for Blocked Queues at Indexer level&lt;BR /&gt;
 4. Splunk Query to check for Missing forwarder.&lt;BR /&gt;
 5. If missing forwarder results, then check for forwarder availability with a ping, followed by a check on splunk socket connection and health check on ports and services.&lt;BR /&gt;
 6. Splunk Query to check for data throttling at forwarder level.&lt;/P&gt;

&lt;P&gt;These are the checks that i have implemented which might cause a missing log source. Checks are only within Splunk Infra.&lt;/P&gt;

&lt;P&gt;Please let me know if i have missed any checks&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2015 10:51:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-End-TO-End-Monitoring/m-p/160862#M7826</guid>
      <dc:creator>lohit</dc:creator>
      <dc:date>2015-06-18T10:51:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk End TO End Monitoring ?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-End-TO-End-Monitoring/m-p/160863#M7827</link>
      <description>&lt;P&gt;I'm trying to develop something similar, would love to see what you have so far if possible?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2015 18:29:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-End-TO-End-Monitoring/m-p/160863#M7827</guid>
      <dc:creator>dmerritt77</dc:creator>
      <dc:date>2015-08-26T18:29:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk End TO End Monitoring ?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-End-TO-End-Monitoring/m-p/160864#M7828</link>
      <description>&lt;P&gt;I have this done and deployed &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2015 07:35:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-End-TO-End-Monitoring/m-p/160864#M7828</guid>
      <dc:creator>lohit</dc:creator>
      <dc:date>2015-08-27T07:35:53Z</dc:date>
    </item>
  </channel>
</rss>

