<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to write a search and alert if any indexers are down? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-search-and-alert-if-any-indexers-are-down/m-p/221139#M64986</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;We have 4 indexers and we need to write a search and set up an alert if any of the indexers is down.&lt;/P&gt;

&lt;P&gt;Can some one please advise on this type of search?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;</description>
    <pubDate>Wed, 24 Feb 2016 20:29:53 GMT</pubDate>
    <dc:creator>splunker9999</dc:creator>
    <dc:date>2016-02-24T20:29:53Z</dc:date>
    <item>
      <title>How to write a search and alert if any indexers are down?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-search-and-alert-if-any-indexers-are-down/m-p/221139#M64986</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;We have 4 indexers and we need to write a search and set up an alert if any of the indexers is down.&lt;/P&gt;

&lt;P&gt;Can some one please advise on this type of search?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2016 20:29:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-search-and-alert-if-any-indexers-are-down/m-p/221139#M64986</guid>
      <dc:creator>splunker9999</dc:creator>
      <dc:date>2016-02-24T20:29:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to write a search and alert if any indexers are down?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-search-and-alert-if-any-indexers-are-down/m-p/221140#M64987</link>
      <description>&lt;P&gt;You probably don't need to write such a search yourself. You should start with the overview dashboard in the Distributed Management Console. It will show you your deployment topology and whether any indexers are down. If you have not configured the Distributed Management Console, see &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.3.3/DMC/DMCoverview"&gt;the Distributed Management Console&lt;/A&gt; documentation.&lt;/P&gt;

&lt;P&gt;If you are using indexer clustering, the &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.3.3/Indexer/Howtomonitoracluster"&gt;cluster master dashboard&lt;/A&gt; will also show you what indexers are up and down.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2016 20:46:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-search-and-alert-if-any-indexers-are-down/m-p/221140#M64987</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2016-02-24T20:46:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to write a search and alert if any indexers are down?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-search-and-alert-if-any-indexers-are-down/m-p/221141#M64988</link>
      <description>&lt;P&gt;This would be useful to monitor, but we are looking for a alert to be recieved whenever indexer is down?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2016 20:58:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-search-and-alert-if-any-indexers-are-down/m-p/221141#M64988</guid>
      <dc:creator>splunker9999</dc:creator>
      <dc:date>2016-02-24T20:58:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to write a search and alert if any indexers are down?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-search-and-alert-if-any-indexers-are-down/m-p/221142#M64989</link>
      <description>&lt;P&gt;But you could set up an alert from the dashboard search, couldn't you?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2016 21:05:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-search-and-alert-if-any-indexers-are-down/m-p/221142#M64989</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2016-02-24T21:05:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to write a search and alert if any indexers are down?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-search-and-alert-if-any-indexers-are-down/m-p/221143#M64990</link>
      <description>&lt;P&gt;We are new to the Splunk and need some assistance, Can you please help us?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2016 21:10:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-search-and-alert-if-any-indexers-are-down/m-p/221143#M64990</guid>
      <dc:creator>splunker9999</dc:creator>
      <dc:date>2016-02-24T21:10:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to write a search and alert if any indexers are down?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-search-and-alert-if-any-indexers-are-down/m-p/221144#M64991</link>
      <description>&lt;P&gt;The DMC has preconfigured alerts for what you want.  Enable the "Search Peer Not Responding" alert.&lt;/P&gt;

&lt;P&gt;DMC Alert - Abnormal State of Indexer Processor [edit]&lt;BR /&gt;
One or more of your indexers is reporting an abnormal state.&lt;/P&gt;

&lt;P&gt;DMC Alert - Critical System Physical Memory Usage [edit]&lt;BR /&gt;
One or more instances has exceeded 90% memory usage.&lt;/P&gt;

&lt;P&gt;DMC Alert - Expired and Soon To Expire Licenses [edit]&lt;BR /&gt;
You have licenses that expire or will expire within two weeks.&lt;/P&gt;

&lt;P&gt;DMC Alert - Missing forwarders [edit]&lt;BR /&gt;
One or more forwarders are missing.&lt;/P&gt;

&lt;P&gt;DMC Alert - Near Critical Disk Usage [edit]&lt;BR /&gt;
You have used 80% of your disk capacity.&lt;/P&gt;

&lt;P&gt;DMC Alert - Saturated Event-Processing Queues [edit]&lt;BR /&gt;
One or more of your indexer queues is reporting a fill percentage, averaged over the last 15 minutes, of 90% or more.&lt;/P&gt;

&lt;P&gt;DMC Alert - Search Peer Not Responding [edit]&lt;BR /&gt;
One or more of your search peers is currently down.&lt;/P&gt;

&lt;P&gt;DMC Alert - Total License Usage Near Daily Quota [edit]&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2016 21:18:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-write-a-search-and-alert-if-any-indexers-are-down/m-p/221144#M64991</guid>
      <dc:creator>bmacias84</dc:creator>
      <dc:date>2016-02-24T21:18:08Z</dc:date>
    </item>
  </channel>
</rss>

