Getting Data In

overall splunk monitoring

andersmholmgren
Explorer

What is needed to monitor that splunk is running properly.

There is the Deployment Monitor App (http://splunk-base.splunk.com/apps/22301/splunk-deployment-monitor) as well as the SoS app (http://splunk-base.splunk.com/apps/29008/sos-splunk-on-splunk), but is that all that is needed?

Isn't there some kind of monitoring outside of splunk that is needed - e.g. monitoring that splunk processes (splunkd, splunkweb) are running? Any pointers around an overall monitoring strategy?

Tags (1)
1 Solution

MuS
SplunkTrust
SplunkTrust

Hi andersmholmgren

like any other IT system/server Splunk as well needs basic monitoring from the outside. a good start is for sure to monitor the two processes mentioned by you, but also keep in mind that there could be much more involved like SAN, NFS, network and so on.

hope this helps

cheers

View solution in original post

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi andersmholmgren

like any other IT system/server Splunk as well needs basic monitoring from the outside. a good start is for sure to monitor the two processes mentioned by you, but also keep in mind that there could be much more involved like SAN, NFS, network and so on.

hope this helps

cheers

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi andersmholmgren

the most important process is the one you get with 'splunk status' listed as first, this is the main splunkd:

splunkd is running (PID: xxxxx).
splunk helpers are running (PIDs: xxxxx xxxxx).
splunkweb is running (PID: xxxxx).

other splunkd's are helpers and searches which makes no sense to monitor those - because as you said they come and go 😉

0 Karma

shivang14
New Member

Hi Mus,
How can we monitor the SBOX hosting Splunk environment ?
Can Splunk monitor its own OS and Hardware on which it is hosted ?
What is the best practivce to monitor SBOX ?
Regards
Shivang Kanoujia

0 Karma

andersmholmgren
Explorer

Thanks MuS

Do you know of a good reference for the processes to monitor and their lifecycles?

I've noticed that splunkd instances seem to come and go if I'm not mistaken.

0 Karma

shivang14
New Member

Hi Mus,
How can we monitor the SBOX hosting Splunk environment ?
Can Splunk monitor its own OS and Hardware on which it is hosted ?
What is the best practivce to monitor SBOX ?
Regards
Shivang Kanoujia

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...