<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to create alert for server / forwarder / index that doesn't work? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/How-to-create-alert-for-server-forwarder-index-that-doesn-t-work/m-p/444675#M7805</link>
    <description>&lt;P&gt;Ok thanks but here's another question:&lt;/P&gt;

&lt;P&gt;Any way I can make these alerts pop on the search heads too? Currently it's only a triggered alert on the indexer master node.&lt;/P&gt;</description>
    <pubDate>Mon, 16 Jul 2018 08:34:44 GMT</pubDate>
    <dc:creator>agentsofshield</dc:creator>
    <dc:date>2018-07-16T08:34:44Z</dc:date>
    <item>
      <title>How to create alert for server / forwarder / index that doesn't work?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-create-alert-for-server-forwarder-index-that-doesn-t-work/m-p/444673#M7803</link>
      <description>&lt;P&gt;In order to find out more quickly if a certain part of Splunk doesn't work, I figured that maybe there's a way to create an alert in case one of these things doesn't work?:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Server (if any server is down - search, indexer, deployment, etc.)&lt;/LI&gt;
&lt;LI&gt;Forwarder&lt;/LI&gt;
&lt;LI&gt;Index (I'd like to check on important indexes we use all the time)&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;I want an alert in case one of these doesn't work. Anyone knows how?&lt;/P&gt;

&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jul 2018 06:54:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-create-alert-for-server-forwarder-index-that-doesn-t-work/m-p/444673#M7803</guid>
      <dc:creator>agentsofshield</dc:creator>
      <dc:date>2018-07-16T06:54:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to create alert for server / forwarder / index that doesn't work?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-create-alert-for-server-forwarder-index-that-doesn-t-work/m-p/444674#M7804</link>
      <description>&lt;P&gt;Hi @agentsofshield ,&lt;/P&gt;

&lt;P&gt;You could use monitoring console (Old DMC)for that. Please have a look at this  &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.1.2/DMC/Platformalerts"&gt;http://docs.splunk.com/Documentation/Splunk/7.1.2/DMC/Platformalerts&lt;/A&gt;&lt;BR /&gt;
AND&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.1.2/DMC/Configureforwardermonitoring"&gt;http://docs.splunk.com/Documentation/Splunk/7.1.2/DMC/Configureforwardermonitoring&lt;/A&gt;&lt;BR /&gt;
AND&lt;BR /&gt;
In general : &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.1.2/DMC/Monitoringoverview"&gt;http://docs.splunk.com/Documentation/Splunk/7.1.2/DMC/Monitoringoverview&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Please lets know in case you need further help&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jul 2018 07:52:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-create-alert-for-server-forwarder-index-that-doesn-t-work/m-p/444674#M7804</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2018-07-16T07:52:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to create alert for server / forwarder / index that doesn't work?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-create-alert-for-server-forwarder-index-that-doesn-t-work/m-p/444675#M7805</link>
      <description>&lt;P&gt;Ok thanks but here's another question:&lt;/P&gt;

&lt;P&gt;Any way I can make these alerts pop on the search heads too? Currently it's only a triggered alert on the indexer master node.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jul 2018 08:34:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-create-alert-for-server-forwarder-index-that-doesn-t-work/m-p/444675#M7805</guid>
      <dc:creator>agentsofshield</dc:creator>
      <dc:date>2018-07-16T08:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to create alert for server / forwarder / index that doesn't work?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-create-alert-for-server-forwarder-index-that-doesn-t-work/m-p/444676#M7806</link>
      <description>&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.1.2/DMC/WheretohostDMC"&gt;http://docs.splunk.com/Documentation/Splunk/7.1.2/DMC/WheretohostDMC&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jul 2018 08:41:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-create-alert-for-server-forwarder-index-that-doesn-t-work/m-p/444676#M7806</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2018-07-16T08:41:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to create alert for server / forwarder / index that doesn't work?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-create-alert-for-server-forwarder-index-that-doesn-t-work/m-p/444677#M7807</link>
      <description>&lt;P&gt;Ok, what about indexes? Can I check if an index brings back results and if it doesn't, create an alert?&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jul 2018 10:58:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-create-alert-for-server-forwarder-index-that-doesn-t-work/m-p/444677#M7807</guid>
      <dc:creator>agentsofshield</dc:creator>
      <dc:date>2018-07-16T10:58:38Z</dc:date>
    </item>
  </channel>
</rss>

