Getting Data In

Alert when Splunk Universal Forwarder stops working/if uninstalled


How can I get alerts when Splunk UF is uninstalled on a Windows Machine? Or even if the SplunkForwarder Service is Stopped?
Is there anyway?

0 Karma

Ultra Champion

Start maybe with the generic query -

    | metadata type=hosts index=* 
    | eval host=lower(host) 
    | eval _time=recentTime 
    | sort host, _time 
    | stats latest(_time) as recentTime by host 
    | eval LAST=strftime(recentTime,"%a %m/%d/%Y-%T %Z(%z)"), DAYS_AGO=round((recentTime-now())/86400,0) 
0 Karma

Splunk Employee
Splunk Employee

You can find a list of forwarders in the monitoring console under Settings, monitoring console (or DMC for older versions), then select Forwarders, Forwarders: deployment. In the Status and Configuration section, open the report in search (magnifying glass icon). Once in the search mode, you can adjust the search query to your specific needs and Save As an alert.

0 Karma