Deployment Architecture

How can i find only SH replication errors ?

egid_la
Explorer

I'm currently running Splunk 6.5.3

I want to create a KPI based on search heads replication errors.

I found this search :

index="_internal" sourcetype=splunkd replicate log_level=ERROR component=SHCRepJob

I can see search heads on host fields but it seem to be too much result.

alt text

Have a better idea ?

How can i find all replications errors (lookup, etc ..) ?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In January, the Splunk Threat Research Team had one release of new security content via the Splunk ES Content ...

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...