<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alert if any forwarder stops sending in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Alert-if-any-forwarder-stops-sending/m-p/53632#M740</link>
    <description>&lt;P&gt;Try the Splunk Deployment Monitor App,  it has built in Forwarder Monitoring and Alerting :&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Missing Forwarder(s)&lt;/LI&gt;
&lt;LI&gt;Quiet Forwarder(s)&lt;/LI&gt;
&lt;LI&gt;Forwarder(s) Sending Less Than Expected&lt;/LI&gt;
&lt;LI&gt;Forwarder(s) Sending More Than Expected&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Wed, 16 May 2012 22:24:42 GMT</pubDate>
    <dc:creator>Damien_Dallimor</dc:creator>
    <dc:date>2012-05-16T22:24:42Z</dc:date>
    <item>
      <title>Alert if any forwarder stops sending</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-if-any-forwarder-stops-sending/m-p/53631#M739</link>
      <description>&lt;P&gt;I want to extend the ideas for "Send an alert if machine x" stops sending data, and build the "A forwarder has gone away" alert&lt;/P&gt;

&lt;P&gt;How can I write an alert that tells me if we have received no data from an individual machine, without having to specify the machine.  I've successfully used the answers here for single machines, but I want to make it universal, and not have to either change the search or add a new one every time I start to monitor a new machine.&lt;/P&gt;

&lt;P&gt;The problem is that all the answers I have found here (admittedly, there may be some I missed) need you to identify the machine.  What I want to use for example is the absence of Windows Security Log events to find that a Windows Forwarder has dropped off, similarly Syslog on my Solaris machines, but without naming the host.&lt;/P&gt;

&lt;P&gt;Any suggestions?&lt;/P&gt;</description>
      <pubDate>Wed, 16 May 2012 21:50:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-if-any-forwarder-stops-sending/m-p/53631#M739</guid>
      <dc:creator>au_chrismor</dc:creator>
      <dc:date>2012-05-16T21:50:52Z</dc:date>
    </item>
    <item>
      <title>Re: Alert if any forwarder stops sending</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-if-any-forwarder-stops-sending/m-p/53632#M740</link>
      <description>&lt;P&gt;Try the Splunk Deployment Monitor App,  it has built in Forwarder Monitoring and Alerting :&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Missing Forwarder(s)&lt;/LI&gt;
&lt;LI&gt;Quiet Forwarder(s)&lt;/LI&gt;
&lt;LI&gt;Forwarder(s) Sending Less Than Expected&lt;/LI&gt;
&lt;LI&gt;Forwarder(s) Sending More Than Expected&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 16 May 2012 22:24:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-if-any-forwarder-stops-sending/m-p/53632#M740</guid>
      <dc:creator>Damien_Dallimor</dc:creator>
      <dc:date>2012-05-16T22:24:42Z</dc:date>
    </item>
    <item>
      <title>Re: Alert if any forwarder stops sending</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-if-any-forwarder-stops-sending/m-p/53633#M741</link>
      <description>&lt;P&gt;Thanks Damien.&lt;/P&gt;

&lt;P&gt;I found the answer in DM just as your reply came in...  Appreciate it&lt;/P&gt;</description>
      <pubDate>Wed, 16 May 2012 23:20:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-if-any-forwarder-stops-sending/m-p/53633#M741</guid>
      <dc:creator>au_chrismor</dc:creator>
      <dc:date>2012-05-16T23:20:24Z</dc:date>
    </item>
  </channel>
</rss>

