Getting Data In

create notable event for missing forwarders

jg91
Path Finder

Hi, is there any solution to create a notable event for missing forwarders? Now missing forwarders generate an alert on Monitoring Console, which runs on a separate Splunk instance than ES.

 

Labels (2)
0 Karma

Vardhan
Contributor

Hi,

You can write a correlation search for missing forwarders and select the alert type as a notable event.And you will get all the missing forwarder alerts as a notable event.

0 Karma

jg91
Path Finder

Hi,
Yes, but I want to find a way to forward MC Missing Forwarders Alerts to ES as a Notable Event, not creating a new Correlation search.

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...