How do I check to see if all my Indexers are healthy & universal & heavy forwarders are healthy & reporting in?
Since this is only alerting/reporting application using mostly _internal logs. Any search head would be fine or you can install it only on your Monitoring Console instance.
Since ES has its own datamodels, you need to install on ES to access datamodel definitions.
There are a few Cluster Master searches that runs via REST calls, that is why it will be install there too.
There is no need to install indexers. You should install it on any search head, and Cluster Master and ES for datamodel specific alerts.
You can find more detail on Installation part of the details page;
https://splunkbase.splunk.com/app/3796/#/details
One last question please. So If I have 3 Search heads I install it on each SH ? In addition to install it on CM & ES ? Thank u in advance. Stay blessed & safe.
Since this is only alerting/reporting application using mostly _internal logs. Any search head would be fine or you can install it only on your Monitoring Console instance.
Since ES has its own datamodels, you need to install on ES to access datamodel definitions.
There are a few Cluster Master searches that runs via REST calls, that is why it will be install there too.
Hi @SamHTexas,
You can check Alerts for Splunk Admin app (https://splunkbase.splunk.com/app/3796/).
It has lots of alerts categorized by indexers, forwarders, search heads etc.
You can schedule the relevant ones to your infrastructure.
Thank you for your message. Where is best to install this app. ? On any search head? Indexer? ES? I will wait for your reply & Thx