Alerting

Alerting on missing data

Crashfry
Path Finder

Looking to see what others do for missing data - an example being a universal forwarder on a linux server, stops sending logs from bash history for root.. assuming it's a source type - what are others doing to make sure an alert is triggered when a situation similar happens? Any help would be great!

Tags (1)
1 Solution

pkeenan87
Communicator

I am a big fan of the meta woot app. You can repurpose some of the dashboard searches into alerts: https://splunkbase.splunk.com/app/2949/#/details

View solution in original post

0 Karma

lakshman239
Influencer

You can have a list of sourcetypes which you want to monitor in a lookup along with max allowed delay time and using metadata, you can monitor them.
https://answers.splunk.com/answers/730503/query-to-see-the-forwarder-does-not-send-logs.html#answer-...

0 Karma

pkeenan87
Communicator

I am a big fan of the meta woot app. You can repurpose some of the dashboard searches into alerts: https://splunkbase.splunk.com/app/2949/#/details

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...