Monitoring Splunk

Log sources not reporting

sahildb
Engager

Currently our index= windows host not reporting from last couple of days.

 

Need query to set up alert if log sources are not reporting to splunk.

Labels (1)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @sahildb,

You can use below query to find hosts that is not reporting for 60 minutes by host, index and sourcetype.

| tstats max(_time) as _time where index=* by index host sourcetype | where _time < relative_time(now(),"-60m")

 You can adapt 60 minutes timeout and indexes to your need. 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @sahildb,

You can use Broken Hosts app to monitor your data ingestion problems,

https://splunkbase.splunk.com/app/3247/

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

sahildb
Engager

Is there any query we can use to detect ?

0 Karma

sahildb
Engager

Thanks for the solution i think will recommend the same to team.

 

 

0 Karma

sahildb
Engager

Need to verify and set up alert which index generate data and or not and how we can monitor

0 Karma
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...