Getting Data In

monitoring splunk server(s)

mflamerich
Explorer

Hi,
I would like to know if there is a 'best practice' document around the topic of monitoring and alerting about a splunk server health.
What would be the recommendation to implement a monitor on "splunkd" ?
I have alerts in case a forwarder is sending less than expected, but how do I send alerts if splunkd has crashed?
I would like to know if there is a splunk solution for this kind of alerting, so I will not have to install another monitor (Nagios, BigBrother) to monitor splunk.

Tags (1)
1 Solution

MHibbin
Influencer

Splunk released an App (apologies if you have heard of it), it's called S.o.S (Splunk on Splunk).

Within this App, amongst a whole host of other useful things, there is a section on errors, and you can select errors from splunkd there.

You can download it here... http://splunk-base.splunk.com/apps/29008/sos-splunk-on-splunk

View solution in original post

MHibbin
Influencer

Splunk released an App (apologies if you have heard of it), it's called S.o.S (Splunk on Splunk).

Within this App, amongst a whole host of other useful things, there is a section on errors, and you can select errors from splunkd there.

You can download it here... http://splunk-base.splunk.com/apps/29008/sos-splunk-on-splunk

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Developer Spotlight with Denis Gladkikh

From Splunk Engineer to Kubernetes App Builder Denis GladkikhWhat happens when a lifelong developer turns a ...

Governing Enterprise AI, Bringing Cisco Telemetry Home, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...