Alerting

How to create alert for server / forwarder / index that doesn't work?

agentsofshield
Path Finder

In order to find out more quickly if a certain part of Splunk doesn't work, I figured that maybe there's a way to create an alert in case one of these things doesn't work?:

  • Server (if any server is down - search, indexer, deployment, etc.)
  • Forwarder
  • Index (I'd like to check on important indexes we use all the time)

I want an alert in case one of these doesn't work. Anyone knows how?

Cheers

0 Karma
1 Solution

renjith_nair
Legend

Hi @agentsofshield ,

You could use monitoring console (Old DMC)for that. Please have a look at this http://docs.splunk.com/Documentation/Splunk/7.1.2/DMC/Platformalerts
AND
http://docs.splunk.com/Documentation/Splunk/7.1.2/DMC/Configureforwardermonitoring
AND
In general : http://docs.splunk.com/Documentation/Splunk/7.1.2/DMC/Monitoringoverview

Please lets know in case you need further help

---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

renjith_nair
Legend

Hi @agentsofshield ,

You could use monitoring console (Old DMC)for that. Please have a look at this http://docs.splunk.com/Documentation/Splunk/7.1.2/DMC/Platformalerts
AND
http://docs.splunk.com/Documentation/Splunk/7.1.2/DMC/Configureforwardermonitoring
AND
In general : http://docs.splunk.com/Documentation/Splunk/7.1.2/DMC/Monitoringoverview

Please lets know in case you need further help

---
What goes around comes around. If it helps, hit it with Karma 🙂

agentsofshield
Path Finder

Ok thanks but here's another question:

Any way I can make these alerts pop on the search heads too? Currently it's only a triggered alert on the indexer master node.

0 Karma

renjith_nair
Legend

http://docs.splunk.com/Documentation/Splunk/7.1.2/DMC/WheretohostDMC

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

agentsofshield
Path Finder

Ok, what about indexes? Can I check if an index brings back results and if it doesn't, create an alert?

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...