<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Setting up Alert if jboss service went down in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Setting-up-Alert-if-jboss-service-went-down/m-p/331142#M11007</link>
    <description>&lt;P&gt;Sure! You first create a script which is going to check the jboss status of your machines. You can refer to sample scripts in the below link which will check the jboss status.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://stackoverflow.com/questions/8761374/how-to-check-if-jboss-is-running-on-unix-server"&gt;https://stackoverflow.com/questions/8761374/how-to-check-if-jboss-is-running-on-unix-server&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Save the script in the bin directory of your app and then create an index like you create index normally which will store the result of your script. Then create the inputs.conf in the local directory of your app and give the path to your script. This complete thing is going to index the output of your script. Post the indexing you can set up alerts which will be triggered once it finds "jboss is not running" in your events. I hope this sounds clear. Do let me know if you find any trouble in doing that.&lt;/P&gt;

&lt;P&gt;Thanks!!&lt;/P&gt;</description>
    <pubDate>Tue, 26 Dec 2017 09:36:37 GMT</pubDate>
    <dc:creator>MousumiChowdhur</dc:creator>
    <dc:date>2017-12-26T09:36:37Z</dc:date>
    <item>
      <title>Setting up Alert if jboss service went down</title>
      <link>https://community.splunk.com/t5/Alerting/Setting-up-Alert-if-jboss-service-went-down/m-p/331139#M11004</link>
      <description>&lt;P&gt;I have 3 servers App-1, App-2 and App-3. The three application are running on Jboss. I need a query that Alerts me, if on any servers Jboss Service goes down.&lt;/P&gt;

&lt;P&gt;Any help with this will be appreciated.&lt;/P&gt;

&lt;P&gt;Thank You&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2017 18:04:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Setting-up-Alert-if-jboss-service-went-down/m-p/331139#M11004</guid>
      <dc:creator>shakeel253</dc:creator>
      <dc:date>2017-12-07T18:04:47Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up Alert if jboss service went down</title>
      <link>https://community.splunk.com/t5/Alerting/Setting-up-Alert-if-jboss-service-went-down/m-p/331140#M11005</link>
      <description>&lt;P&gt;Hi @shakeel253,&lt;/P&gt;

&lt;P&gt;You can run a script which will check the jboss status on the machines and index the output of the command in Splunk. Then you can set up an alert on when you get the status as "jboss is not running".&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2017 11:05:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Setting-up-Alert-if-jboss-service-went-down/m-p/331140#M11005</guid>
      <dc:creator>MousumiChowdhur</dc:creator>
      <dc:date>2017-12-20T11:05:08Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up Alert if jboss service went down</title>
      <link>https://community.splunk.com/t5/Alerting/Setting-up-Alert-if-jboss-service-went-down/m-p/331141#M11006</link>
      <description>&lt;P&gt;Can you give an example of how this would be possible?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2017 13:21:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Setting-up-Alert-if-jboss-service-went-down/m-p/331141#M11006</guid>
      <dc:creator>shakeel253</dc:creator>
      <dc:date>2017-12-20T13:21:08Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up Alert if jboss service went down</title>
      <link>https://community.splunk.com/t5/Alerting/Setting-up-Alert-if-jboss-service-went-down/m-p/331142#M11007</link>
      <description>&lt;P&gt;Sure! You first create a script which is going to check the jboss status of your machines. You can refer to sample scripts in the below link which will check the jboss status.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://stackoverflow.com/questions/8761374/how-to-check-if-jboss-is-running-on-unix-server"&gt;https://stackoverflow.com/questions/8761374/how-to-check-if-jboss-is-running-on-unix-server&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Save the script in the bin directory of your app and then create an index like you create index normally which will store the result of your script. Then create the inputs.conf in the local directory of your app and give the path to your script. This complete thing is going to index the output of your script. Post the indexing you can set up alerts which will be triggered once it finds "jboss is not running" in your events. I hope this sounds clear. Do let me know if you find any trouble in doing that.&lt;/P&gt;

&lt;P&gt;Thanks!!&lt;/P&gt;</description>
      <pubDate>Tue, 26 Dec 2017 09:36:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Setting-up-Alert-if-jboss-service-went-down/m-p/331142#M11007</guid>
      <dc:creator>MousumiChowdhur</dc:creator>
      <dc:date>2017-12-26T09:36:37Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up Alert if jboss service went down</title>
      <link>https://community.splunk.com/t5/Alerting/Setting-up-Alert-if-jboss-service-went-down/m-p/331143#M11008</link>
      <description>&lt;P&gt;@Mousumichowdhury i created a shell script and placed it inside /opt/splunkforwarder/bin with executable permission. I also made an entry inside inputs.conf, below is the how the entry looks like inside inputs.conf&lt;/P&gt;

&lt;P&gt;[default]&lt;BR /&gt;
host = svm&lt;BR /&gt;
/opt/splunkforwarder/bin/tomcatscript.sh&lt;/P&gt;

&lt;P&gt;how do you create an index? &lt;/P&gt;</description>
      <pubDate>Tue, 26 Dec 2017 14:44:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Setting-up-Alert-if-jboss-service-went-down/m-p/331143#M11008</guid>
      <dc:creator>shakeel253</dc:creator>
      <dc:date>2017-12-26T14:44:49Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up Alert if jboss service went down</title>
      <link>https://community.splunk.com/t5/Alerting/Setting-up-Alert-if-jboss-service-went-down/m-p/331144#M11009</link>
      <description>&lt;P&gt;@shakeel253, I am afraid you have duplicate questions opened for your JBOSS alerting issues with different description: &lt;A href="https://answers.splunk.com/answers/597751/splunk-query-that-alert-if-services-on-a-jboss-ser.html"&gt;https://answers.splunk.com/answers/597751/splunk-query-that-alert-if-services-on-a-jboss-ser.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Please clarify if this is any different from the other post. Can you try the following? Where hosts will have list of servers you want to monitor and source is the JBOSS log path.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;  | tstats latest(_time) as _time WHERE (host="ABC1" OR host="ABC2" OR host="ABC3") AND source="/opt/jboss-eap/standalone/log/server.log" by host
  | eval "downTime (in Min)"=round((now()-_time)/60,0)
  | append [
      | makeresults
      | eval host="ABC1", "downTime (in Min)"="999"]
  | append [
      | makeresults
      | eval host="ABC2", "downTime (in Min)"="999"]
  | append [
      | makeresults
      | eval host="ABC3", "downTime (in Min)"="999"]
  | dedup host
  | where 'downTime (in Min)'&amp;gt;5
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 26 Dec 2017 17:31:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Setting-up-Alert-if-jboss-service-went-down/m-p/331144#M11009</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2017-12-26T17:31:56Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up Alert if jboss service went down</title>
      <link>https://community.splunk.com/t5/Alerting/Setting-up-Alert-if-jboss-service-went-down/m-p/331145#M11010</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;you can create the index with the below stanza:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[yourindexname]
coldPath = $SPLUNK_DB/yourindexname/colddb
enableDataIntegrityControl = 0
enableTsidxReduction = 0
homePath = $SPLUNK_DB/yourindexname/db
maxTotalDataSizeMB = 512000
thawedPath = $SPLUNK_DB/yourindexname/thaweddb
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If this is a single instance setup then you can place your indexes.conf stanza in /opt/splunk/etc/apps/search/local and in case of clustered environment you can place the indexes.conf file inside /opt/splunk/etc/master-apps//local&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2017 05:14:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Setting-up-Alert-if-jboss-service-went-down/m-p/331145#M11010</guid>
      <dc:creator>MousumiChowdhur</dc:creator>
      <dc:date>2017-12-27T05:14:42Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up Alert if jboss service went down</title>
      <link>https://community.splunk.com/t5/Alerting/Setting-up-Alert-if-jboss-service-went-down/m-p/331146#M11011</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/179778"&gt;@MousumiChowdhur&lt;/a&gt;y i still dont see the new custom index in splunk search. I will describe how my splunk is setup, maybe, i am missing something.&lt;/P&gt;

&lt;P&gt;1) tomcatscript.sh is inside /opt/splunkforwarder/bin&lt;/P&gt;

&lt;H1&gt;!/bin/bash&lt;/H1&gt;

&lt;P&gt;if [ -z "$(ps -ef | grep java | grep tomcat)" ]&lt;BR /&gt;
then&lt;BR /&gt;
 echo "Tomcat is NOT running"&lt;BR /&gt;
else&lt;BR /&gt;
  echo "Tomcat is running"&lt;BR /&gt;
fi&lt;/P&gt;

&lt;P&gt;2) inputs.conf inside /opt/splunkforwarder/etc/apps/search/local&lt;/P&gt;

&lt;P&gt;[monitor:///opt/tomcat/logs/catalina.out]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
index = tomcat&lt;/P&gt;

&lt;P&gt;[monitor:///opt/splunkforwarder/bin/tomcatscript.sh]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
index = tomcatindex&lt;/P&gt;

&lt;P&gt;3)indexes.conf inside /opt/splunkforwarder/etc/apps/search/local&lt;/P&gt;

&lt;P&gt;[tomcatindex]&lt;BR /&gt;
coldPath = $SPLUNK_DB/tomcatindex/colddb&lt;BR /&gt;
enableDataIntegrityControl = 0&lt;BR /&gt;
enableTsidxReduction = 0&lt;BR /&gt;
homePath = $SPLUNK_DB/tomcatindex/db&lt;BR /&gt;
maxTotalDataSizeMB = 512000&lt;BR /&gt;
thawedPath = $SPLUNK_DB/tomcatindex/thaweddb&lt;/P&gt;

&lt;P&gt;when i do a search on splunk host="abcvm" but the only index i see is "os". I also did a restart as well for the splunkforwarder but didnt see the newly created index. Maybe i am doing something wrong, would appreciate if you could direct me, thank you&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:26:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Setting-up-Alert-if-jboss-service-went-down/m-p/331146#M11011</guid>
      <dc:creator>shakeel253</dc:creator>
      <dc:date>2020-09-29T17:26:37Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up Alert if jboss service went down</title>
      <link>https://community.splunk.com/t5/Alerting/Setting-up-Alert-if-jboss-service-went-down/m-p/331147#M11012</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;

&lt;P&gt;Follow the below steps for the single instance:&lt;/P&gt;

&lt;P&gt;Create your script in &lt;CODE&gt;/opt/splunk/etc/apps/search/bin/&lt;/CODE&gt;&lt;BR /&gt;
Create your inputs.conf in &lt;CODE&gt;/opt/splunk/etc/apps/search/local/&lt;/CODE&gt;&lt;BR /&gt;
Create your indexes.conf in &lt;CODE&gt;/opt/splunk/etc/apps/search/local/&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Follow the below steps for clustered set up:&lt;/P&gt;

&lt;P&gt;Create your script in &lt;CODE&gt;/opt/splunk/etc/deployment-apps/&amp;lt;yourappname&amp;gt;/bin/&lt;/CODE&gt;&lt;BR /&gt;
Create your inputs.conf in &lt;CODE&gt;/opt/splunk/etc/deployment-apps/&amp;lt;yourappname&amp;gt;/local/&lt;/CODE&gt;&lt;BR /&gt;
Create your indexes.conf in &lt;CODE&gt;/opt/splunk/etc/master-apps/&amp;lt;yourappname&amp;gt;/local/&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Do let me know if that's working for you.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2017 05:02:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Setting-up-Alert-if-jboss-service-went-down/m-p/331147#M11012</guid>
      <dc:creator>MousumiChowdhur</dc:creator>
      <dc:date>2017-12-28T05:02:55Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up Alert if jboss service went down</title>
      <link>https://community.splunk.com/t5/Alerting/Setting-up-Alert-if-jboss-service-went-down/m-p/331148#M11013</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/179778"&gt;@MousumiChowdhur&lt;/a&gt;y &lt;/P&gt;

&lt;P&gt;firstoff thank you for assisting me with this, having said that bin directory is not inside /opt/splunk/etc/apps/search, so i had to manually create  the bin folder and gave it splunk ownership and copy the tomcat script inside bin.&lt;/P&gt;

&lt;P&gt;2) This is how the indexes.conf &lt;/P&gt;

&lt;P&gt;[&lt;A href="mailto:root@ip-xx.xxx.xx.xxx" target="_blank"&gt;root@ip-xx.xxx.xx.xxx&lt;/A&gt; local]# cat indexes.conf&lt;BR /&gt;
[tomcatindex]&lt;BR /&gt;
coldPath = $SPLUNK_DB/tomcatindex/colddb&lt;BR /&gt;
enableDataIntegrityControl = 0&lt;BR /&gt;
enableTsidxReduction = 0&lt;BR /&gt;
homePath = $SPLUNK_DB/tomcatindex/db&lt;BR /&gt;
maxTotalDataSizeMB = 512000&lt;BR /&gt;
thawedPath = $SPLUNK_DB/tomcatindex/thaweddb&lt;/P&gt;

&lt;P&gt;[tomcatindex]&lt;BR /&gt;
coldPath = /opt/splunkforwarder/etc/apps/search/bin/./tomcatscript.sh&lt;BR /&gt;
enableDataIntegrityControl = 0&lt;BR /&gt;
enableTsidxReduction = 0&lt;BR /&gt;
homePath = /opt/splunkforwarder/etc/apps/search/bin/./tomcatscript.sh&lt;BR /&gt;
maxTotalDataSizeMB = 512000&lt;BR /&gt;
thawedPath = /opt/splunkforwarder/etc/apps/search/bin/./tomcatscript.sh&lt;/P&gt;

&lt;P&gt;3)[root@ip-xx-xxx-xx-xx local]# cat inputs.conf&lt;BR /&gt;
[monitor:///opt/tomcat/logs/catalina.out]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
index = tomcat&lt;/P&gt;

&lt;P&gt;[monitor:///opt/splunkforwarder/bin/tomcatscript.sh]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
index = tomcatindex&lt;/P&gt;

&lt;P&gt;[monitor:///opt/splunkforwarder/etc/apps/search/bin/./tomcatscript.sh]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
index = tomcatindex&lt;/P&gt;

&lt;P&gt;After making these changes, i have restarted splunkforwarder and search for the index, but i do not see the index still, what am i missing?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:27:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Setting-up-Alert-if-jboss-service-went-down/m-p/331148#M11013</guid>
      <dc:creator>shakeel253</dc:creator>
      <dc:date>2020-09-29T17:27:04Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up Alert if jboss service went down</title>
      <link>https://community.splunk.com/t5/Alerting/Setting-up-Alert-if-jboss-service-went-down/m-p/331149#M11014</link>
      <description>&lt;P&gt;Hi, may I know why are you creating the files in your splunkforwarder?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jan 2018 06:22:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Setting-up-Alert-if-jboss-service-went-down/m-p/331149#M11014</guid>
      <dc:creator>MousumiChowdhur</dc:creator>
      <dc:date>2018-01-05T06:22:32Z</dc:date>
    </item>
  </channel>
</rss>

