Hello,
I want a dashboard where I can see if the OS on a Windows machine is still running or got shutdown/crashed.
My Idea was:
If there is no no data for 20 minutes there should be an alert that something is wrong.
I'm thankful for every bit of help!
Best regards
Timo
Hi,
Try to check Forwarder health app, you can get an idea on search queries you can use which you can use for any other generic purpose.
-Krishna Rajapantula
Another way to check if splunk is down is to search your _internal index for phone homes from that host. Or a powers hell script to perform a test-connection against the host as a scripted input