I have two search heads and a cluster master.
Need to create an alert after "apply shcluster bundle" from cluster master to SH's. But the bundle push is from Octopus deployer and I created a role for that and kept the cmd in .bat file
My requirement is to create an alert after the Update done or after the bundle push from master.
Try running this search
index=_internal sourcetype=splunkd_conf component=ConfDeployment
Can you explain me clearly... I want to create an alert with which will trigger after the Octopus deployment from cluster master ?