Is there an easy way to export / monitor / alert on the warning / alert messages in Splunk?
By this I mean the messages you see in the GUI like running low on space / license alert / you need to restart splunk etc. I want these to feed into our monitoring system (nagios) automatically.
You may have to check out this app:
http://apps.splunk.com/app/352/
This is a cool app , whatever you show in op5 monitoring dashboard , you will have a similiar feel..
You might need to carefully read the settings for configuring this..
You might need to correlate the Nagios events with the messages and set alerts...
Have you worked on lookups ?
Yeah we're working on this already. But does it allow to take the built in 'messages' in splunk (not scheduled search alerts) and send them to nagios?