<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to use Splunkweb alert to run a script on the forwarder to restart a service? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/How-to-use-Splunkweb-alert-to-run-a-script-on-the-forwarder-to/m-p/414059#M7241</link>
    <description>&lt;P&gt;No.. What I suggested was creating a script on your SH. Then have that script SSH to your forwarder and restart the service&lt;/P&gt;</description>
    <pubDate>Fri, 29 Jun 2018 18:40:20 GMT</pubDate>
    <dc:creator>skoelpin</dc:creator>
    <dc:date>2018-06-29T18:40:20Z</dc:date>
    <item>
      <title>How to use Splunkweb alert to run a script on the forwarder to restart a service?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-use-Splunkweb-alert-to-run-a-script-on-the-forwarder-to/m-p/414056#M7238</link>
      <description>&lt;P&gt;Hi I have a service that reports to Splunk and some times fell over, is there any chance I can automate this by telling Splunk to run a scripted input on the forwarder level to restart a service, log it and feed the event to Splunk? &lt;BR /&gt;
Thank you for any answers &lt;BR /&gt;
Or is there any add on that would do that for Linux like HK Systems Management&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jun 2018 13:31:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-use-Splunkweb-alert-to-run-a-script-on-the-forwarder-to/m-p/414056#M7238</guid>
      <dc:creator>max_ruas</dc:creator>
      <dc:date>2018-06-29T13:31:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to use Splunkweb alert to run a script on the forwarder to restart a service?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-use-Splunkweb-alert-to-run-a-script-on-the-forwarder-to/m-p/414057#M7239</link>
      <description>&lt;P&gt;This is probably not the best approach since its a temporary fix. But if you want to proceed then you should do something like this &lt;/P&gt;

&lt;P&gt;Put a script on your SH which will SSH to your forwarder then do a Splunk restart. Have an alert trigger this script when your service falls over&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jun 2018 14:29:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-use-Splunkweb-alert-to-run-a-script-on-the-forwarder-to/m-p/414057#M7239</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2018-06-29T14:29:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to use Splunkweb alert to run a script on the forwarder to restart a service?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-use-Splunkweb-alert-to-run-a-script-on-the-forwarder-to/m-p/414058#M7240</link>
      <description>&lt;P&gt;are you suggesting that in order to run a script on the forwarder I need to do a splunkforwarder restart? can you please clarify your answer?&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jun 2018 14:48:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-use-Splunkweb-alert-to-run-a-script-on-the-forwarder-to/m-p/414058#M7240</guid>
      <dc:creator>max_ruas</dc:creator>
      <dc:date>2018-06-29T14:48:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to use Splunkweb alert to run a script on the forwarder to restart a service?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-use-Splunkweb-alert-to-run-a-script-on-the-forwarder-to/m-p/414059#M7241</link>
      <description>&lt;P&gt;No.. What I suggested was creating a script on your SH. Then have that script SSH to your forwarder and restart the service&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jun 2018 18:40:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-use-Splunkweb-alert-to-run-a-script-on-the-forwarder-to/m-p/414059#M7241</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2018-06-29T18:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to use Splunkweb alert to run a script on the forwarder to restart a service?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-use-Splunkweb-alert-to-run-a-script-on-the-forwarder-to/m-p/414060#M7242</link>
      <description>&lt;P&gt;Thanks for the answer I think is valid although Is not what I am looking for as its much more complex that it needs to be, I am looking for some thing like this.. I haven't got around to test yet but I'm hoping it works. &lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answering/232172/view.html"&gt;https://answers.splunk.com/answering/232172/view.html&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 03 Jul 2018 06:18:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-use-Splunkweb-alert-to-run-a-script-on-the-forwarder-to/m-p/414060#M7242</guid>
      <dc:creator>max_ruas</dc:creator>
      <dc:date>2018-07-03T06:18:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to use Splunkweb alert to run a script on the forwarder to restart a service?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-use-Splunkweb-alert-to-run-a-script-on-the-forwarder-to/m-p/414061#M7243</link>
      <description>&lt;P&gt;I've found a solution on the forwarder app it self. on linux is under &lt;BR /&gt;
cat /opt/splunkforwarder/bin/scripts/readme.txt&lt;BR /&gt;
&lt;STRONG&gt;Scripts placed in this directory can be called by Alerts for execution&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;if you define your scheduled search as an alert, you can configure a script to be run whenever the alert is triggered. For security reasons, the scripts need to be placed in a specific folder like the above.&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.2/Alert/Setupalertactions#Run_a_script_for_an_alert_action"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.2/Alert/Setupalertactions#Run_a_script_for_an_alert_action&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 03 Jul 2018 06:30:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-use-Splunkweb-alert-to-run-a-script-on-the-forwarder-to/m-p/414061#M7243</guid>
      <dc:creator>max_ruas</dc:creator>
      <dc:date>2018-07-03T06:30:01Z</dc:date>
    </item>
  </channel>
</rss>

