Deployment Architecture

How can i find only SH replication errors ?

egid_la
Explorer

I'm currently running Splunk 6.5.3

I want to create a KPI based on search heads replication errors.

I found this search :

index="_internal" sourcetype=splunkd replicate log_level=ERROR component=SHCRepJob

I can see search heads on host fields but it seem to be too much result.

alt text

Have a better idea ?

How can i find all replications errors (lookup, etc ..) ?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...