Getting Data In

Missing sourcetype from a particular device

surekhasplunk
Communicator

I have a list of 10 sourcetypes and a list of 14 ips . If a particular ip stops sending data for any sourcetype in last 6 hours i should be alerted. How to set it.
I tried metadata sourcetype but that gives only missing sourcetypes.
If i use only metadata host i get only missing hosts
but how to get a combination of missing host and sourcetype.

Tags (2)
0 Karma
1 Solution

manjunathmeti
Champion

Hi @surekhasplunk,

Use metasearch, replace SOURCETYPEs and HOSTs in below query and check.

| metasearch index=INDEXNAME
| stats count by sourcetype, host 
| append 
    [| makeresults 
    | eval sourcetype=split("SOURCETYPE1,SOURCETYPE2,SOURCETYPE3,...,SOURCETYPE10", ","), host=split("HOST1,HOST2,HOST3,....,HOST14", ",") 
    | mvexpand sourcetype 
    | mvexpand host 
    | fields - _time] 
| fillnull value=0 
| stats sum(count) as count by sourcetype, host 
| where count=0

And set Trigger Condition as Number of result greater than 0 in alert configuration.

View solution in original post

0 Karma

manjunathmeti
Champion

Hi @surekhasplunk,

Use metasearch, replace SOURCETYPEs and HOSTs in below query and check.

| metasearch index=INDEXNAME
| stats count by sourcetype, host 
| append 
    [| makeresults 
    | eval sourcetype=split("SOURCETYPE1,SOURCETYPE2,SOURCETYPE3,...,SOURCETYPE10", ","), host=split("HOST1,HOST2,HOST3,....,HOST14", ",") 
    | mvexpand sourcetype 
    | mvexpand host 
    | fields - _time] 
| fillnull value=0 
| stats sum(count) as count by sourcetype, host 
| where count=0

And set Trigger Condition as Number of result greater than 0 in alert configuration.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...