My customer want to monitoring the following 2 things:
1. The status of logs collection. Thats means they wan to ensure that all logs were indexed to splunk.
2. The status of splunk. Send the splunk web message (like the message in the image) to their centralized monitoring platform them in real time if there are any warn or error occured because they almost don't care about splunk monitoring console.
@aojie654 If you want to look at log collection and the data indexed, the LM has the capability and you can just extract that search and modify it to meet client requirement. Maybe create another dashboard out of it