Getting Data In

Can i use Splunk to monitor windows scheduled jobs?

sampathkonka
New Member

We're having a few Batch Jobs scheduled using windows task scheduler. In certain situations the batch jobs are not triggering or failing to run. Currently every day we're manually monitoring whether the jobs are running without any issues or not. Is it possible to monitor those scheduled tasks are running or not using Splunk? if so can i send a real time alert in case of job fail using Splunk?

These Jobs are scheduled in remote server where we're having Splunk Universal forwarder.

Could you please assist with the solution for above use case.

Thanking you,

Regards,
Sampath Konka.

0 Karma
1 Solution

somesoni2
SplunkTrust
SplunkTrust

The windows scheduler task logs are written to Application Event logs. You can setup monitoring for those specific event logs to first get the data in Splunk. Once you've data in Splunk you can setup alerting. See this for more details.
http://docs.splunk.com/Documentation/SplunkCloud/6.6.0/Data/MonitorWindowseventlogdata#Use_the_.22Fu...

Howevers, instead of using a real-time alert, I would recommend using a regular scheduled alert with appropriate frequency/cron schedule.

View solution in original post

0 Karma

somesoni2
SplunkTrust
SplunkTrust

The windows scheduler task logs are written to Application Event logs. You can setup monitoring for those specific event logs to first get the data in Splunk. Once you've data in Splunk you can setup alerting. See this for more details.
http://docs.splunk.com/Documentation/SplunkCloud/6.6.0/Data/MonitorWindowseventlogdata#Use_the_.22Fu...

Howevers, instead of using a real-time alert, I would recommend using a regular scheduled alert with appropriate frequency/cron schedule.

0 Karma

santosh_sshanbh
Path Finder

Thanks for the link bwlm. This really helps.

0 Karma

bwlm
Path Finder

The link to the "SplunkCloud" docs apparently require a logon, for general public details here is a better link: https://docs.splunk.com/Documentation/Splunk/latest/Data/MonitorWindowseventlogdata#Use_the_.22Full_...

0 Karma

sampathkonka
New Member

Hi Somesoni2,

Thanking you for your inputs. I'll have a look into the above URL to get solution for above posted use case.

Sorry for the delay in response.

Sampath Konka

0 Karma

sampathkonka
New Member

Thanking you So much Somesoni2,

I'm able to read the windows scheduler task logs from remote server using Splunk forwarder 🙂

Regards,
Sampath Konka.

0 Karma

santosh_sshanbh
Path Finder

Can you please provide details on how did you achived this? In my case I am not seeing any events in Application windows log.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...