<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to find when splunk is not indexing? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/How-to-find-when-splunk-is-not-indexing/m-p/135602#M2182</link>
    <description>&lt;P&gt;Cool. I'd recommend looking at the troubleshooting documentation that @lmyrefelt provided in their answer above. Splunk logs a lot of useful data on itself to help you pinpoint if there are any problems in your environment (ex: if all indexing has stopped entirely). There's a list of the different internal logs in that documentation and a description of what each one contains. So if something has stopped working out of the blue, you would usually look through or run searches against these internal logs for errors on the instances where the problem is happening.&lt;/P&gt;

&lt;P&gt;You can very well still use the approach of searching the count of events in your environment via the REST API and triggering an alert if you are getting zero results for a certain amount of time. Since you just started using Splunk yesterday and might not be familiar with how frequently you'll be indexing events, it might be hard to assume what window of time you should be alerting on. 5 minutes might be too strict of a number. Again, I'm not an expert on this so I can't give you a concrete answer, but hopefully this will be a good starting point with things to think about moving forward.&lt;/P&gt;</description>
    <pubDate>Thu, 12 Feb 2015 02:30:42 GMT</pubDate>
    <dc:creator>ppablo</dc:creator>
    <dc:date>2015-02-12T02:30:42Z</dc:date>
    <item>
      <title>How to find when splunk is not indexing?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-find-when-splunk-is-not-indexing/m-p/135592#M2172</link>
      <description>&lt;P&gt;Is there any way to find out if splunk stopped indexing? I would like to send a notification when splunk stops indexing.&lt;/P&gt;

&lt;P&gt;For notification i will use scoutapp or i may just send an email.&lt;/P&gt;

&lt;P&gt;OS --&amp;gt; production ubuntu / Development Mac&lt;BR /&gt;
We are using distributed system and get log from multiple servers.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Feb 2015 06:34:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-find-when-splunk-is-not-indexing/m-p/135592#M2172</guid>
      <dc:creator>irakeshraut</dc:creator>
      <dc:date>2015-02-11T06:34:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to find when splunk is not indexing?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-find-when-splunk-is-not-indexing/m-p/135593#M2173</link>
      <description>&lt;P&gt;There are plenty. Can you provide us with more information ? How is your architecture ? OS ?&lt;BR /&gt;
Do you want to use Splunk to monitor it self ? &lt;/P&gt;

&lt;P&gt;Have you read the docs ? &lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/Whatsinhere"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/Whatsinhere&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;There is also plenty of good apps now-a-days for your day-to-day monitoring and troubleshooting of splunk at apps.splunk.com&lt;/P&gt;</description>
      <pubDate>Wed, 11 Feb 2015 19:17:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-find-when-splunk-is-not-indexing/m-p/135593#M2173</guid>
      <dc:creator>lmyrefelt</dc:creator>
      <dc:date>2015-02-11T19:17:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to find when splunk is not indexing?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-find-when-splunk-is-not-indexing/m-p/135594#M2174</link>
      <description>&lt;P&gt;I will use &lt;CODE&gt;scoutapp&lt;/CODE&gt; to monitor &lt;CODE&gt;splunk&lt;/CODE&gt;. But only difficulty is to find when splunk is not indexing so i can send the alert.&lt;/P&gt;

&lt;P&gt;I was thinking about doing search using &lt;CODE&gt;splunk api&lt;/CODE&gt; and search for &lt;CODE&gt;index=*&lt;/CODE&gt; for last &lt;CODE&gt;5 minute&lt;/CODE&gt;( I am not sure if its possible). If there is no result from our search then send the alert. I am pretty sure there must be smarter way of doing this.&lt;/P&gt;

&lt;P&gt;Can i use &lt;CODE&gt;eventcount&lt;/CODE&gt; for this ? or any other better way?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Feb 2015 23:25:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-find-when-splunk-is-not-indexing/m-p/135594#M2174</guid>
      <dc:creator>irakeshraut</dc:creator>
      <dc:date>2015-02-11T23:25:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to find when splunk is not indexing?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-find-when-splunk-is-not-indexing/m-p/135595#M2175</link>
      <description>&lt;P&gt;How is this different from your previous posting? &lt;A href="http://answers.splunk.com/answers/214857/how-to-find-out-if-splunk-is-indexing-data.html"&gt;http://answers.splunk.com/answers/214857/how-to-find-out-if-splunk-is-indexing-data.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Feb 2015 23:36:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-find-when-splunk-is-not-indexing/m-p/135595#M2175</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2015-02-11T23:36:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to find when splunk is not indexing?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-find-when-splunk-is-not-indexing/m-p/135596#M2176</link>
      <description>&lt;P&gt;Ya i have posted 3 question so far. All related to same think because I haven't got working solution so far.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Feb 2015 00:50:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-find-when-splunk-is-not-indexing/m-p/135596#M2176</guid>
      <dc:creator>irakeshraut</dc:creator>
      <dc:date>2015-02-12T00:50:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to find when splunk is not indexing?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-find-when-splunk-is-not-indexing/m-p/135597#M2177</link>
      <description>&lt;P&gt;How about answering to actual question rather than digging what I am asking? &lt;/P&gt;</description>
      <pubDate>Thu, 12 Feb 2015 00:51:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-find-when-splunk-is-not-indexing/m-p/135597#M2177</guid>
      <dc:creator>irakeshraut</dc:creator>
      <dc:date>2015-02-12T00:51:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to find when splunk is not indexing?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-find-when-splunk-is-not-indexing/m-p/135598#M2178</link>
      <description>&lt;P&gt;Hi @irakeshraut&lt;/P&gt;

&lt;P&gt;@ChrisG is just trying to help with decluttering this forum. If you are going to post questions with duplicate content, please delete your previous posts so there aren't 3 of the same topic here on Splunk Answers. Each time you've posted a brand new (same) question, you haven't been providing enough details for users to work with and they have to keep asking you for extra information. When someone has attempted to answered your questions, that's when you've been providing extra information on how you're trying to achieve your goal, but at that point, they’re probably on to their own priorities. &lt;/P&gt;

&lt;P&gt;This is a free space to find answers, so it's not like users are going to be sitting watching a post the entire day and can't wait for a back and forth thread to get all the details they need to give you a full and complete answer. If @ChrisG and I were REST API experts, then we’d be more than happy and willing to answer your questions, but unfortunately we’re not. What we’re trying to do is optimize your posts so you can find the right experts here on Splunk Answers to help you find your solutions. We’re all trying to help each other out here in this space, all we ask is that users be respectful to each other.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Feb 2015 01:53:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-find-when-splunk-is-not-indexing/m-p/135598#M2178</guid>
      <dc:creator>ppablo</dc:creator>
      <dc:date>2015-02-12T01:53:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to find when splunk is not indexing?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-find-when-splunk-is-not-indexing/m-p/135599#M2179</link>
      <description>&lt;P&gt;Pulling information from your other 2 posts and this one, you should consider rephrasing your question and content (if you choose to post a new question, I would post it in 15 hours when traffic on the site is high AND delete all your previous posts with the same content):&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Question:&lt;/STRONG&gt; &lt;BR /&gt;
How to search the count of indexed events in the last 5 minutes via REST API and send an alert if the count is 0?&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Information you should provide in your content:&lt;/STRONG&gt;&lt;BR /&gt;
-What version of Splunk are you running?&lt;BR /&gt;
-On what operating system?&lt;BR /&gt;
-What is your architecture? (single instance, distributed search, etc)&lt;BR /&gt;
-Be as detailed as possible with what you’re trying to achieve, your desired outcome, and HOW you want to get there. (ex: you  haven’t been putting in your content that you’re trying to do this via the REST API, so users aren’t going to just assume that by default)&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Other information to consider:&lt;/STRONG&gt;&lt;BR /&gt;
Are you trying to find out if Splunk has stopped indexing, or if there just aren't any events indexed in the last 5 minutes? These are two different things, but you’ve been asking both interchangeably. Checking if Splunk has stopped indexing implies something has broken. How frequently are you expecting data to be indexed? Just because there were no events in the last 5 minutes doesn’t mean Splunk has stopped indexing, so you could be getting false positives.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Feb 2015 01:53:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-find-when-splunk-is-not-indexing/m-p/135599#M2179</guid>
      <dc:creator>ppablo</dc:creator>
      <dc:date>2015-02-12T01:53:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to find when splunk is not indexing?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-find-when-splunk-is-not-indexing/m-p/135600#M2180</link>
      <description>&lt;P&gt;Thanks makes sense &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Feb 2015 02:02:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-find-when-splunk-is-not-indexing/m-p/135600#M2180</guid>
      <dc:creator>irakeshraut</dc:creator>
      <dc:date>2015-02-12T02:02:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to find when splunk is not indexing?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-find-when-splunk-is-not-indexing/m-p/135601#M2181</link>
      <description>&lt;P&gt;Thanks for your reply. I am actually trying to find if splunk has stopped indexing. &lt;/P&gt;</description>
      <pubDate>Thu, 12 Feb 2015 02:05:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-find-when-splunk-is-not-indexing/m-p/135601#M2181</guid>
      <dc:creator>irakeshraut</dc:creator>
      <dc:date>2015-02-12T02:05:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to find when splunk is not indexing?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-find-when-splunk-is-not-indexing/m-p/135602#M2182</link>
      <description>&lt;P&gt;Cool. I'd recommend looking at the troubleshooting documentation that @lmyrefelt provided in their answer above. Splunk logs a lot of useful data on itself to help you pinpoint if there are any problems in your environment (ex: if all indexing has stopped entirely). There's a list of the different internal logs in that documentation and a description of what each one contains. So if something has stopped working out of the blue, you would usually look through or run searches against these internal logs for errors on the instances where the problem is happening.&lt;/P&gt;

&lt;P&gt;You can very well still use the approach of searching the count of events in your environment via the REST API and triggering an alert if you are getting zero results for a certain amount of time. Since you just started using Splunk yesterday and might not be familiar with how frequently you'll be indexing events, it might be hard to assume what window of time you should be alerting on. 5 minutes might be too strict of a number. Again, I'm not an expert on this so I can't give you a concrete answer, but hopefully this will be a good starting point with things to think about moving forward.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Feb 2015 02:30:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-find-when-splunk-is-not-indexing/m-p/135602#M2182</guid>
      <dc:creator>ppablo</dc:creator>
      <dc:date>2015-02-12T02:30:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to find when splunk is not indexing?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-find-when-splunk-is-not-indexing/m-p/135603#M2183</link>
      <description>&lt;P&gt;Well, Splunk can have "stopped" indexing based on a "Number" of factors ... including a lot of them that might have nothing to do with splunk itself ... (i.e.. network, application, etc, etc) You are probably better of monitoring the Splunkd process and or its open ports 8089 ? At least in addition to a search to be able to determine if it really is Splunk that stopped indexing data or if it is Something blocking data from reaching splunk. &lt;/P&gt;

&lt;P&gt;And your scout-app seems to be able to do it all.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Feb 2015 08:50:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-find-when-splunk-is-not-indexing/m-p/135603#M2183</guid>
      <dc:creator>lmyrefelt</dc:creator>
      <dc:date>2015-02-12T08:50:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to find when splunk is not indexing?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-find-when-splunk-is-not-indexing/m-p/135604#M2184</link>
      <description>&lt;P&gt;Thanks for your reply. We are already monitoring splunkd using scoutapp. &lt;/P&gt;</description>
      <pubDate>Thu, 12 Feb 2015 09:55:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-find-when-splunk-is-not-indexing/m-p/135604#M2184</guid>
      <dc:creator>irakeshraut</dc:creator>
      <dc:date>2015-02-12T09:55:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to find when splunk is not indexing?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-find-when-splunk-is-not-indexing/m-p/135605#M2185</link>
      <description>&lt;P&gt;You can also use the distributed management console. It has an indexing performance dashboard and related platform alerts. The docs for it are in the Admin Manual, starting with the topic &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.1/Admin/ConfiguretheMonitoringConsole"&gt;Configure the distributed management console&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Feb 2015 16:56:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-find-when-splunk-is-not-indexing/m-p/135605#M2185</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2015-02-12T16:56:38Z</dc:date>
    </item>
  </channel>
</rss>

