Alerting

Is it possible to trigger a restart script on forwarder when an alert condition is met?

krishnacasso
Path Finder

Hi,

We monitor server status using access live log. It will continuously check for 200 statuses from the log. When we have status other than 200, for 5 minutes we need to trigger an alert. I see a option in +add action to run a script. Can we place a restart script on the server where the forwarder is installed and trigger it whenever the alert condition in triggered?

Thanks.

0 Karma

Masa
Splunk Employee
Splunk Employee

There is such built-in feature to access forwarder from a search head where you trigger a post script. So, you have to create your own scripts to make it work like that.

0 Karma

krishnacasso
Path Finder

Thanks Masa,
Do we need to manually access the forwarder from UI or Is there a way to automate this.

Thanks.

0 Karma

Masa
Splunk Employee
Splunk Employee

It depends. Your system admin should be able to advise how to remotely run command or access to remote server by script.

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...