Getting Data In

monitoring splunk server(s)

mflamerich
Explorer

Hi,
I would like to know if there is a 'best practice' document around the topic of monitoring and alerting about a splunk server health.
What would be the recommendation to implement a monitor on "splunkd" ?
I have alerts in case a forwarder is sending less than expected, but how do I send alerts if splunkd has crashed?
I would like to know if there is a splunk solution for this kind of alerting, so I will not have to install another monitor (Nagios, BigBrother) to monitor splunk.

Tags (1)
1 Solution

MHibbin
Influencer

Splunk released an App (apologies if you have heard of it), it's called S.o.S (Splunk on Splunk).

Within this App, amongst a whole host of other useful things, there is a section on errors, and you can select errors from splunkd there.

You can download it here... http://splunk-base.splunk.com/apps/29008/sos-splunk-on-splunk

View solution in original post

MHibbin
Influencer

Splunk released an App (apologies if you have heard of it), it's called S.o.S (Splunk on Splunk).

Within this App, amongst a whole host of other useful things, there is a section on errors, and you can select errors from splunkd there.

You can download it here... http://splunk-base.splunk.com/apps/29008/sos-splunk-on-splunk

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mastering Threat Intelligence in ES 8.5, Splunk AI Assistant v2, and More from Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...