<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitor index activity in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Monitor-index-activity/m-p/580887#M47597</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;there are many apps which you can use for this. Here is some of those and other information about missing events.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;There are a lot of options for finding hosts or sources that stop submitting events:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Meta Woot!&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://splunkbase.splunk.com/app/2949/" target="_blank" rel="noopener noreferrer"&gt;https://splunkbase.splunk.com/app/2949/&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;TrackMe&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://splunkbase.splunk.com/app/4621/" target="_blank" rel="noopener noreferrer"&gt;https://splunkbase.splunk.com/app/4621/&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;Broken Hosts App for Splunk&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://splunkbase.splunk.com/app/3247/" target="_blank" rel="noopener noreferrer"&gt;https://splunkbase.splunk.com/app/3247/&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;Alerts for Splunk Admins ("ForwarderLevel" alerts)&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://splunkbase.splunk.com/app/3796/" target="_blank" rel="noopener noreferrer"&gt;https://splunkbase.splunk.com/app/3796/&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;Monitoring Console&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/DMC/Configureforwardermonitoring" target="_blank" rel="noopener noreferrer"&gt;https://docs.splunk.com/Documentation/Splunk/latest/DMC/Configureforwardermonitoring&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;Deployment Server&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs.splunk.com/Documentation/DepMon/latest/DeployDepMon/Troubleshootyourdeployment#Forwarder_warnings" target="_blank" rel="noopener noreferrer"&gt;https://docs.splunk.com/Documentation/DepMon/latest/DeployDepMon/Troubleshootyourdeployment#Forwarder_warnings&lt;/A&gt;&lt;SPAN&gt;Some helpful posts:&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="https://lantern.splunk.com/hc/en-us/articles/360048503294-Hosts-logging-data-in-a-certain-timeframe" target="_blank" rel="noopener noreferrer"&gt;https://lantern.splunk.com/hc/en-us/articles/360048503294-Hosts-logging-data-in-a-certain-timeframe&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://www.duanewaddle.com/proving-a-negative/" target="_blank" rel="noopener noreferrer"&gt;https://www.duanewaddle.com/proving-a-negative/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You could easily add alert based on those.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
    <pubDate>Thu, 13 Jan 2022 07:00:21 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2022-01-13T07:00:21Z</dc:date>
    <item>
      <title>Monitor index activity</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Monitor-index-activity/m-p/580875#M47595</link>
      <description>&lt;P&gt;Hi there, I would like to monitor indexes that have not been active for more than 24hrs+ and display the names of the indexes in a table as well as the last received activity. Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jan 2022 04:06:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Monitor-index-activity/m-p/580875#M47595</guid>
      <dc:creator>x3ncrypt</dc:creator>
      <dc:date>2022-01-13T04:06:54Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor index activity</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Monitor-index-activity/m-p/580887#M47597</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;there are many apps which you can use for this. Here is some of those and other information about missing events.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;There are a lot of options for finding hosts or sources that stop submitting events:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Meta Woot!&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://splunkbase.splunk.com/app/2949/" target="_blank" rel="noopener noreferrer"&gt;https://splunkbase.splunk.com/app/2949/&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;TrackMe&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://splunkbase.splunk.com/app/4621/" target="_blank" rel="noopener noreferrer"&gt;https://splunkbase.splunk.com/app/4621/&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;Broken Hosts App for Splunk&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://splunkbase.splunk.com/app/3247/" target="_blank" rel="noopener noreferrer"&gt;https://splunkbase.splunk.com/app/3247/&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;Alerts for Splunk Admins ("ForwarderLevel" alerts)&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://splunkbase.splunk.com/app/3796/" target="_blank" rel="noopener noreferrer"&gt;https://splunkbase.splunk.com/app/3796/&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;Monitoring Console&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/DMC/Configureforwardermonitoring" target="_blank" rel="noopener noreferrer"&gt;https://docs.splunk.com/Documentation/Splunk/latest/DMC/Configureforwardermonitoring&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;Deployment Server&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs.splunk.com/Documentation/DepMon/latest/DeployDepMon/Troubleshootyourdeployment#Forwarder_warnings" target="_blank" rel="noopener noreferrer"&gt;https://docs.splunk.com/Documentation/DepMon/latest/DeployDepMon/Troubleshootyourdeployment#Forwarder_warnings&lt;/A&gt;&lt;SPAN&gt;Some helpful posts:&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="https://lantern.splunk.com/hc/en-us/articles/360048503294-Hosts-logging-data-in-a-certain-timeframe" target="_blank" rel="noopener noreferrer"&gt;https://lantern.splunk.com/hc/en-us/articles/360048503294-Hosts-logging-data-in-a-certain-timeframe&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://www.duanewaddle.com/proving-a-negative/" target="_blank" rel="noopener noreferrer"&gt;https://www.duanewaddle.com/proving-a-negative/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You could easily add alert based on those.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jan 2022 07:00:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Monitor-index-activity/m-p/580887#M47597</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-01-13T07:00:21Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor index activity</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Monitor-index-activity/m-p/580891#M47598</link>
      <description>&lt;P&gt;| tstats latest(_time) as latest where index=* earliest=-24h by host,index | eval status = if(latest &amp;gt; relative_time(now(),"-23h"),"Success","Faliure"), Time = strftime(latest,"%c")|table host,Tindex,time,status&lt;/P&gt;&lt;P&gt;this will do&amp;nbsp;&lt;/P&gt;&lt;P&gt;or use apps in&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;'s reply&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jan 2022 07:14:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Monitor-index-activity/m-p/580891#M47598</guid>
      <dc:creator>SinghK</dc:creator>
      <dc:date>2022-01-13T07:14:02Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor index activity</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Monitor-index-activity/m-p/580893#M47599</link>
      <description>&lt;P&gt;Mostly right, but you're going to miss index that is offline for 25h+.&lt;/P&gt;&lt;P&gt;Should search for a longer time span, something like this:&lt;/P&gt;&lt;P&gt;| tstats max(_time) AS _time WHERE earliest=-7d@d BY index&lt;BR /&gt;| where _time&amp;lt;now()-(24*3600)&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jan 2022 07:19:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Monitor-index-activity/m-p/580893#M47599</guid>
      <dc:creator>johnhuang</dc:creator>
      <dc:date>2022-01-13T07:19:10Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor index activity</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Monitor-index-activity/m-p/581949#M47679</link>
      <description>&lt;P&gt;Is that the entire search string I will need to use? Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jan 2022 05:10:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Monitor-index-activity/m-p/581949#M47679</guid>
      <dc:creator>x3ncrypt</dc:creator>
      <dc:date>2022-01-21T05:10:57Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor index activity</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Monitor-index-activity/m-p/581962#M47682</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;based on&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/190794"&gt;@johnhuang&lt;/a&gt;&amp;nbsp;SPL some modifications. If you want to check towards all indexes what you have defined on your indexers and don't want to get data from all time with tstats you should use this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| tstats max(_time) as _time where earliest=-1d@d by index 
| append 
    [| rest /services/data/indexes splunk_server=*
    | fields title 
    | rename title as index 
    | eval _time=0] 
| where _time&amp;lt;now()-(24*3600)&lt;/LI-CODE&gt;&lt;P&gt;Just replace splunk_server=* with your indexers.&lt;/P&gt;&lt;P&gt;This just get list of your all indexes which are defined on indexers and then get events from the beginning of previous day.&lt;/P&gt;&lt;P&gt;r. Ismo&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jan 2022 07:23:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Monitor-index-activity/m-p/581962#M47682</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-01-21T07:23:40Z</dc:date>
    </item>
  </channel>
</rss>

