Alerting

Alert when both devices in HA pair stop reporting

gstefancyk
Path Finder

I currently have an alert setup to send email when one of our infoblox servers stops sending logs based on metadata of the index and a csv lookup for hosts. This works well but the issue I am running into is that some of the devices are in an HA pair so I am constantly getting emails for the backup device not reporting. Below is my current search,

| metadata type=hosts index=infoblox
| lookup infoblox_hosts.csv host_ip as host OUTPUT host_ip as host, server_name as server
| search host=*
| where lastTime < (now() - 86400)
| convert ctime(lastTime) as LastTimeLogged
| table host,server LastTimeLogged
| sort LastTimeLogged

Can someone point me in the right direction to setup a condition to alert when both server1 and server2 have stopped reporting otherwise do nothing?

Thanks

Tags (1)
0 Karma
1 Solution

maciep
Champion

is there anything in your lookup that identifies which servers are part of the HA pair? maybe another column that identifies the HA IP for example?

If so, then you might be able to just worry about the latest event from that vip. Something like:

| metadata type=hosts index=infoblox 
| lookup infoblox_hosts.csv host_ip as host OUTPUT host_ip as host, server_name as server, ha_ip as vip
| search host=*
| eventstats max(lastTime) as vip_lastTime by vip
| where vip_lastTime < (now() - 86400)
| convert ctime(vip_lastTime) as LastTimeLogged
| table host,server LastTimeLogged

View solution in original post

0 Karma

maciep
Champion

is there anything in your lookup that identifies which servers are part of the HA pair? maybe another column that identifies the HA IP for example?

If so, then you might be able to just worry about the latest event from that vip. Something like:

| metadata type=hosts index=infoblox 
| lookup infoblox_hosts.csv host_ip as host OUTPUT host_ip as host, server_name as server, ha_ip as vip
| search host=*
| eventstats max(lastTime) as vip_lastTime by vip
| where vip_lastTime < (now() - 86400)
| convert ctime(vip_lastTime) as LastTimeLogged
| table host,server LastTimeLogged
0 Karma

gstefancyk
Path Finder

Thanks for the suggestion, I will give this a try and see happens.

0 Karma

gstefancyk
Path Finder

Thanks maciep, works as expected after adding 3rd column to my lookup table.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...