Alerting

How to configure a Heartbeat alert in a Search Head Cluster

gcusello
SplunkTrust
SplunkTrust

Hi at all,
I have a Search Head Cluster with 3 SHs that sends alerts to an external system based on IBM NetCool.
Cluster deploys alerts between the three Search Heads and ensures that only one of them runs one alert.
My problem is to create a HeartBeat alert that runs on all the three Search Heads every period to be sure that the connection with IBM NetCool is OK.
How can I configure this alert to be executed at the same time on the three Search Heads?

Thank you.
Bye.
Giuseppe

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

I had an answer from Splunk Support: this is not possible.
Bye.
Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

I had an answer from Splunk Support: this is not possible.
Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Infographic provides the TL;DR for the 2024 Splunk Career Impact Report

We’ve been buzzing with excitement about the recent validation of Splunk Education! The 2024 Splunk Career ...

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...