Alerting

Unable to run my query and get correct results.

rudal_0205
Observer

Hi All,

i want a query to check and fire an alert when , there are no logs from a server past 30 min.

For example we have different isnatnce running on a host and i want an alert when there are no logs coming from serevr in past 30 min(because server instances are not running) .So we we dont see any logs from server past 30 min and alert shoul notfiy that server instances are stopped.Please help.

Logs below event.

3/1/24
12:26:07.000 PM
 
www 89589 0 0.0 00:00:02 0.1 51784 2151496 ? S 35:31 httpd -d_/sys_apps_01/apache/server20Cent/versions/server2.4.56_-f_/sys_apps_01/apache/server20Cent/conf/MTF.AEM.conf
Labels (2)
0 Karma

rudal_0205
Observer

I nees a solution from scratch , if someone could help here?

0 Karma

PickleRick
SplunkTrust
SplunkTrust

The question has been answered many times before. @isoutamo already pointed you to a trove of resources for writing such search. If you don't understand some specifics about any of those things said in other threads wiith solutions don't hesitate to ask for explanation. But don't expect people to jump in and do your job for you - the issue is well known and has well known method of dealing with, explained many times. So all you need is to dig into those resources, read the solutions provided there and try to construct your own. If you encounter some obstacles along the way, ask away.

0 Karma

rudal_0205
Observer

Actually i am looking a query on a scenario where there are few istances on my hosts and it went down.Eventually the there were no logs within 2 hrs ..but we find after 2 hrs the logs are captured.So if we find no logs coming from server past 30 min, it should trigger an alert.

0 Karma

isoutamo
SplunkTrust
SplunkTrust
0 Karma

rudal_0205
Observer

Actually i am looking a query on a scenario where there are few istances on my hosts and it went down.Eventually the there were no logs within 2 hrs ..but we find after 2 hrs the logs are captured.So if we find no logs coming from server past 30 min, it should trigger an alert.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...