All Apps and Add-ons

alert for java bridge is not running

Splunk Employee
Splunk Employee

Question: what is the search criteria for java bridge is not running? I want to create an alert that would notify me everytime java bridge is dying abruptly due to memory errors or any other errors . what is the search criteria in jbridge.log or splunkd.log that I should use for java bridge is not running?

Tags (1)

Splunk Employee
Splunk Employee

Let's say we want to receive emails when errors occur (in real time):

(1) create a data input to monitor the logs in real time, add the following entry in dbx/local/inputs.conf

[monitor://$SPLUNK_HOME/var/log/splunk/jbridge.log]
disabled = false
index = main
sourcetype = dbx_jbridge

restart splunk to make it in effect.

(2) in search&report app, create a new search as:

sourcetype=dbx_jbridge ERROR

(3) "Save As" an alert from right menu next to search command bar:

Title: Jbridge Error
Alert type: Real Time
Trigger condition: Per-Result

click on Next

check on List in Triggered Alerts
check on Send Email
fill in email addresses and related information.

Save it.

(4) you need to set up smtp email server connection at settings|server settings|Email settings.
you may either connect to your company's smtp email server or in the local machine, install an email server etc.

(5) An easy test is to kill the jbridge java process then you should receive an email for such errors.

note: jbridge will restart after it is down.

State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!