Server Up-time /down-time

Path Finder

hi, I'm still new to splunk
What search command do I need to run to create a report (or maybe an alert) showing if a server is up or down in real time?

Tags (3)
0 Karma

Esteemed Legend

You need to forward some kind of log or KPI information into Splunk first. Then you search on that data. Let's assume it is Windows and you are sending perfmon into Splunk. You can track one of the KPIs or even the mere presence (or rather lack there of) of events arriving into Splunk to determine if the server is OK or not. Once you get a search working that correctly identifies servers that are down, you just save this search as an Alert and have it send you an email (or trap or whatever) whenever the search returns any results. More details are here:

0 Karma