Alerting

Errors

whitecat001
Explorer

Is there a way to create a Splunk query to show the errors from splunk TA and kv store. 

 
 
Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

can you open little bit more what you’re meaning with this?

Usually those are found from splunk’s internal logs.

r. Ismo

0 Karma

whitecat001
Explorer

What i mean is i want to create a query to output kvstore error and splunk Ta errors 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

All those errors should be on internal logs. Currently quite many TAs are using those too. Those have own log files as a source in _internal. You should just query those from it and look what you have.

0 Karma

whitecat001
Explorer

I want a sample query that will guide in creating one for both TA and Kvstore 

0 Karma
Get Updates on the Splunk Community!

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...