Alerting

CRON ISSUE

jip31
Motivator

Hi

I use a PowerShell script in my SPL command in order to check the ping status of different machines
It works but i think results are not good
i expain : when i launch my SPL command i have machines in offline status or in online status. Normal
but when i m launching the PowerShell alone in the same time a machine can be offline in splunk but online with PowerShell!
the cron i use for executing the PowerShell is */1 * * * *
what i have to do in order to have the same results please??

Tags (2)
0 Karma

DalJeanis
Legend

I don't see any reason to assume that it is a cron issue. I would start by determining at some exact time where splunk says the machine is in one state and Powershell says it is a different state. Note whether it is always one direction, or whether it goes both ways.

There is at least one potential condition in each direction where differences would be valid :

1) If the machine is online but splunk is offline on that machine, then a ping will reach the machine, but splunk will not consider the machine to be up.
2) If the OS executing the ping has lost connectivity to the network, but Splunk has NOT lost connectivity to the network, then the machine will not show as online to the OS but will show online to Splunk.

There are a dozen more scenarios that might happen, depending on the particulars of your configuration. Please post more details, but first verify, in some examples where the detected states differed, verify exactly how the two systems might believe that the system was down at that moment, and see whether it was.

0 Karma

woodcock
Esteemed Legend

We need more details. Show inputs.conf and your searches.

0 Karma

Rob2520
Communicator

How often do you want to run the script?

0 Karma
Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...