Monitoring Splunk

Log sources not reporting

sahildb
Engager

Currently our index= windows host not reporting from last couple of days.

 

Need query to set up alert if log sources are not reporting to splunk.

Labels (1)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @sahildb,

You can use below query to find hosts that is not reporting for 60 minutes by host, index and sourcetype.

| tstats max(_time) as _time where index=* by index host sourcetype | where _time < relative_time(now(),"-60m")

 You can adapt 60 minutes timeout and indexes to your need. 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @sahildb,

You can use Broken Hosts app to monitor your data ingestion problems,

https://splunkbase.splunk.com/app/3247/

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

sahildb
Engager

Is there any query we can use to detect ?

0 Karma

sahildb
Engager

Thanks for the solution i think will recommend the same to team.

 

 

0 Karma

sahildb
Engager

Need to verify and set up alert which index generate data and or not and how we can monitor

0 Karma
Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...