Monitoring Splunk

Sitescope Monitoring

motobeats
Path Finder

We have an extensive Sitescope implementation and would like to use Splunk to display the status of the various monitors.

Any suggestions of where to begin? How do we monitor the status of a monitor? Does Splunk offer stop light graphics that could be used to display status?

Any examples someone could share?

0 Karma

a212830
Champion

You should have a logfile in the logs directory that generates the status of each monitor. In our environment, it's "../logs/SiteScope_YYY_MM_DD.log", which contains all the information you should need to track monitor statuses.

0 Karma

motobeats
Path Finder

I'm ok on the Sitescope side. Was more looking for ideas on how to visualize the info in the logs in Splunk.

0 Karma

motobeats
Path Finder

Do you have links for how to create custom graphics? How about for building a dashboard with the App Framework?

0 Karma

bmacias84
Champion

Sort answer is yes. You can use your own custom graphics or use singles. You can build your won Dashboard app using the App Framework. To get the data you could build an app to query your SiteScope's Database for monitor statuses.

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...