Deployment Architecture

set up an alert for SHC members

bsrikanthreddy5
Path Finder

I have my Search head cluster in AWS and I am looking to set up an alert each time new SHC members get added to the SHC cluster and old members get removed. 


I came across enabling "DMC Alert - Search Peer Not Responding", but it checks for all members (CM, Indexers, SHC members) added to MC . 

Can you please suggest if there is any other way to set up only for SHC members?  

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Probably you should keep inventory for members of that SHC nodes and in regular base run alert which check current situation towards that inventory. When there are changes then update inventory also.

I cannot check exactly commands now, but you could use rest + internal indexes to get those information. More about those e.g. https://community.splunk.com/t5/Deployment-Architecture/Is-there-a-REST-API-call-for-getting-the-sta...

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...