Dashboards & Visualizations

Monitor Indexing on Dashboard

indikaw
Explorer

Hi All,

I have few questions to ask if you can help me.
My Splunk server only has 3 default indexes which are internal, main and audit. I am trying to create a dashboard so I can monitor the indexing activity at a glass everyday morning.

I still can't get the right search string to do this. Can you please let me know how to search for the indexing? So I can put that search in to a dashbord panel. Also then I can set that up for every 24 hours and every morning I can load the dashbord and have an idea about indexing.

Second question is, as same as above how do I get the indexing errors on to a dashboard.

Your help is more that appreciated.

Thanks
Indika

Tags (3)
0 Karma

Drainy
Champion

Pretty wide question.

My first answer would be, use Splunk SoS to check the health and for problems of your indexes. Use the deployment monitor to monitor activity. In reality your indexes should be configured in such a way that you don't need to continually monitor your environment like this. If you do need to then you need to sit down and make sure everything is correctly configured and that your licence meets your needs.
If you really need to then just pull the searches out of the SoS app, they cover everything you need to know (why re-invent the wheel! 🙂 ). If you had anything more specific then just reply back with more detail.

Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...