<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Idle log in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Idle-log/m-p/506043#M141578</link>
    <description>&lt;P&gt;i need script in SPL to show when there is an idle forwarder or if a forwarder isn't forwarding&lt;/P&gt;</description>
    <pubDate>Wed, 24 Jun 2020 19:44:07 GMT</pubDate>
    <dc:creator>saotaigiri</dc:creator>
    <dc:date>2020-06-24T19:44:07Z</dc:date>
    <item>
      <title>Idle log</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Idle-log/m-p/506043#M141578</link>
      <description>&lt;P&gt;i need script in SPL to show when there is an idle forwarder or if a forwarder isn't forwarding&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2020 19:44:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Idle-log/m-p/506043#M141578</guid>
      <dc:creator>saotaigiri</dc:creator>
      <dc:date>2020-06-24T19:44:07Z</dc:date>
    </item>
    <item>
      <title>Re: Idle log</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Idle-log/m-p/506044#M141579</link>
      <description>The Monitoring Console has an alert for that. Go to Settings-&amp;gt;Monitoring Console-&amp;gt;Settings-&amp;gt;Alerts setup and look for "DMC Alert - Missing forwarders".</description>
      <pubDate>Wed, 24 Jun 2020 19:46:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Idle-log/m-p/506044#M141579</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-06-24T19:46:44Z</dc:date>
    </item>
    <item>
      <title>Re: Idle log</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Idle-log/m-p/506045#M141580</link>
      <description>&lt;P&gt;It is greyed out, should i enable it?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2020 19:50:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Idle-log/m-p/506045#M141580</guid>
      <dc:creator>saotaigiri</dc:creator>
      <dc:date>2020-06-24T19:50:44Z</dc:date>
    </item>
    <item>
      <title>Re: Idle log</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Idle-log/m-p/506048#M141582</link>
      <description>If you want to receive alerts about missing forwarders then, yes, you should enable it.</description>
      <pubDate>Wed, 24 Jun 2020 20:07:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Idle-log/m-p/506048#M141582</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-06-24T20:07:38Z</dc:date>
    </item>
    <item>
      <title>Re: Idle log</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Idle-log/m-p/506315#M141657</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;The server was turned off to test if the alert would work but t did not work. Please what can I do&amp;nbsp; to get an alert&amp;nbsp; where the forwarder is not getting any&amp;nbsp; data&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2020 15:51:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Idle-log/m-p/506315#M141657</guid>
      <dc:creator>saotaigiri</dc:creator>
      <dc:date>2020-06-26T15:51:56Z</dc:date>
    </item>
    <item>
      <title>Re: Idle log</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Idle-log/m-p/506336#M141669</link>
      <description>"It did not work" doesn't help narrow the problem.&lt;BR /&gt;An alternative to the DMC alert is to create your own search for forwarder data. Save the search as an alert and have the alert trigger when the number of results is zero.</description>
      <pubDate>Fri, 26 Jun 2020 17:53:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Idle-log/m-p/506336#M141669</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-06-26T17:53:54Z</dc:date>
    </item>
    <item>
      <title>Re: Idle log</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Idle-log/m-p/506575#M141719</link>
      <description>&lt;P&gt;Thanks for your reply, please could help to write the SPL query. I am not good at writing SPL queries.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2020 18:36:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Idle-log/m-p/506575#M141719</guid>
      <dc:creator>saotaigiri</dc:creator>
      <dc:date>2020-06-29T18:36:15Z</dc:date>
    </item>
    <item>
      <title>Re: Idle log</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Idle-log/m-p/506597#M141728</link>
      <description>I can help. What do you have so far?</description>
      <pubDate>Mon, 29 Jun 2020 20:53:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Idle-log/m-p/506597#M141728</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-06-29T20:53:06Z</dc:date>
    </item>
    <item>
      <title>Re: Idle log</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Idle-log/m-p/506763#M141762</link>
      <description>&lt;P&gt;The query below is what I am using but it doesn't seem to work. Please can you look at it and if possible tweak to the correct one.&lt;/P&gt;&lt;P&gt;| rest /services/server/info | eval LastStartupTime=strftime(startuptime, "%Y/%m/%d %H:%M:%S")&lt;BR /&gt;| eval timenow=now()&lt;BR /&gt;| eval daysup = round((timenow - startuptime) / 86400,0)&lt;BR /&gt;| eval Uptime = tostring(daysup) + " Days"&lt;BR /&gt;| table splunk_server LastStartupTime Uptime&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am looking to get an alert when&amp;nbsp; a server or host meant to be feeding Splunk goes down. Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2020 17:58:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Idle-log/m-p/506763#M141762</guid>
      <dc:creator>saotaigiri</dc:creator>
      <dc:date>2020-06-30T17:58:24Z</dc:date>
    </item>
    <item>
      <title>Re: Idle log</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Idle-log/m-p/506774#M141763</link>
      <description>&lt;P&gt;That &lt;FONT face="courier new,courier"&gt;rest&lt;/FONT&gt; command will get you the status of your Splunk instances (indexers, search heads, etc), but not your forwarders&lt;/P&gt;&lt;P&gt;Try this query I found in the Splunk Security Essentials app. You should modify the &lt;FONT face="courier new,courier"&gt;index&lt;/FONT&gt; and &lt;FONT face="courier new,courier"&gt;sourcetype&lt;/FONT&gt; parameters to suit for environment.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| tstats prestats=t count(host) where index=* groupby host _time span=1d 
| tstats prestats=t append=t count where index=* sourcetype=* by host  _time span=1d 
| stats count(host) as all_logs count as win_logs by host _time 
| eval win_perc=round(100*(win_logs / all_logs), 2) 
| eventstats max(_time) as maxtime 
| stats count as num_data_samples avg(eval(if(_time&amp;lt;relative_time(maxtime, "-1d@d"), win_perc, null))) as avg sum(eval(if(_time&amp;lt;relative_time(maxtime, "-1d@d") AND win_perc=0, 1, null))) as past_instances_of_no_logs max(eval(if(_time&amp;gt;=relative_time(maxtime, "-1d@d"), win_perc, null))) as latest by host 
| where isnotnull(avg) AND num_data_samples&amp;gt;10 AND isnull(past_instances_of_no_logs) AND latest=0&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2020 19:02:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Idle-log/m-p/506774#M141763</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-06-30T19:02:15Z</dc:date>
    </item>
  </channel>
</rss>

