Alerting

Is it possible to trigger a restart script on forwarder when an alert condition is met?

krishnacasso
Path Finder

Hi,

We monitor server status using access live log. It will continuously check for 200 statuses from the log. When we have status other than 200, for 5 minutes we need to trigger an alert. I see a option in +add action to run a script. Can we place a restart script on the server where the forwarder is installed and trigger it whenever the alert condition in triggered?

Thanks.

0 Karma

Masa
Splunk Employee
Splunk Employee

There is such built-in feature to access forwarder from a search head where you trigger a post script. So, you have to create your own scripts to make it work like that.

0 Karma

krishnacasso
Path Finder

Thanks Masa,
Do we need to manually access the forwarder from UI or Is there a way to automate this.

Thanks.

0 Karma

Masa
Splunk Employee
Splunk Employee

It depends. Your system admin should be able to advise how to remotely run command or access to remote server by script.

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

  Ready to master Kubernetes and cloud monitoring like the pros?Join Splunk’s Growth Engineering team for an ...

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...