Monitoring Splunk

Log sources not reporting

sahildb
Engager

Currently our index= windows host not reporting from last couple of days.

 

Need query to set up alert if log sources are not reporting to splunk.

Labels (1)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @sahildb,

You can use below query to find hosts that is not reporting for 60 minutes by host, index and sourcetype.

| tstats max(_time) as _time where index=* by index host sourcetype | where _time < relative_time(now(),"-60m")

 You can adapt 60 minutes timeout and indexes to your need. 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @sahildb,

You can use Broken Hosts app to monitor your data ingestion problems,

https://splunkbase.splunk.com/app/3247/

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

sahildb
Engager

Is there any query we can use to detect ?

0 Karma

sahildb
Engager

Thanks for the solution i think will recommend the same to team.

 

 

0 Karma

sahildb
Engager

Need to verify and set up alert which index generate data and or not and how we can monitor

0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...