Getting Data In

Is there a way to get a service status from a remote centos8 machine?

tazzvon
Engager

is there anyway to setup something on a dashboard that will tell me if a service on a remote centos box goes down.

I run arkime on a centos8 box and i want a dashboard in splunk that will show me the status of the services

arkimecaprute.service

arkimeviewer.service

elasticsearch.service

is this possible?

Labels (2)
Tags (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Are these services regularly logging? If you ingest the logs into splunk, you can search for when each service last logged a message and use that to determine if the service is up (and logging) or not.

0 Karma

tazzvon
Engager

the only way the service logs is if i use a cron job and when i tried that i realized the UF will only forward if the log has changed which is good but not in this instance since only 1 word really changes and does not always trigger the UF to read it. This is a sort of solution but i was wondering if there was a better one out there that i was just not aware of.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...